CVE-2026-44434: CWE-345: Insufficient Verification of Data Authenticity in h2o quicly
Quicly, the QUIC protocol implementation used in the H2O HTTP server, had a vulnerability allowing stateless reset injection due to insufficient verification of secret pattern slots. This flaw could let an on-path attacker reset QUIC connections by exploiting zero-initialized pattern slots treated as valid resets. The issue was fixed by a specific commit (dccf5d4). The vulnerability has a medium severity with a CVSS score of 5.3 and impacts availability without affecting confidentiality or integrity.
AI Analysis
Technical Summary
CVE-2026-44434 describes a vulnerability in Quicly, an IETF QUIC protocol implementation for the H2O HTTP server. Prior to commit dccf5d4, Quicly did not properly validate which of the four secret pattern slots used for stateless resets contained valid entries. Because these slots were zero-initialized, an all-zero pattern was mistakenly accepted as a valid stateless reset unless the peer advertised all four patterns. This allowed an on-path attacker to inject stateless reset packets and forcibly reset QUIC connections. The vulnerability affects availability but not confidentiality or integrity. The issue has been fixed by the referenced commit.
Potential Impact
An attacker with network access could inject stateless reset packets to forcibly terminate QUIC connections managed by Quicly, causing denial of service. There is no impact on confidentiality or integrity of data. The CVSS score of 5.3 reflects a medium severity denial of service vulnerability exploitable remotely without privileges or user interaction.
Mitigation Recommendations
A fix for this vulnerability was introduced in commit dccf5d4. Since no official patch or vendor advisory is provided here, patch status is not yet confirmed — check the vendor advisory or project repository for the commit and apply the fix accordingly. Until patched, be aware of the potential for connection resets caused by this flaw.
CVE-2026-44434: CWE-345: Insufficient Verification of Data Authenticity in h2o quicly
Description
Quicly, the QUIC protocol implementation used in the H2O HTTP server, had a vulnerability allowing stateless reset injection due to insufficient verification of secret pattern slots. This flaw could let an on-path attacker reset QUIC connections by exploiting zero-initialized pattern slots treated as valid resets. The issue was fixed by a specific commit (dccf5d4). The vulnerability has a medium severity with a CVSS score of 5.3 and impacts availability without affecting confidentiality or integrity.
CVSS v3.1
Score 5.3medium
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-44434 describes a vulnerability in Quicly, an IETF QUIC protocol implementation for the H2O HTTP server. Prior to commit dccf5d4, Quicly did not properly validate which of the four secret pattern slots used for stateless resets contained valid entries. Because these slots were zero-initialized, an all-zero pattern was mistakenly accepted as a valid stateless reset unless the peer advertised all four patterns. This allowed an on-path attacker to inject stateless reset packets and forcibly reset QUIC connections. The vulnerability affects availability but not confidentiality or integrity. The issue has been fixed by the referenced commit.
Potential Impact
An attacker with network access could inject stateless reset packets to forcibly terminate QUIC connections managed by Quicly, causing denial of service. There is no impact on confidentiality or integrity of data. The CVSS score of 5.3 reflects a medium severity denial of service vulnerability exploitable remotely without privileges or user interaction.
Mitigation Recommendations
A fix for this vulnerability was introduced in commit dccf5d4. Since no official patch or vendor advisory is provided here, patch status is not yet confirmed — check the vendor advisory or project repository for the commit and apply the fix accordingly. Until patched, be aware of the potential for connection resets caused by this flaw.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-05-06T14:40:00.954Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a59635868715ace43da39ce
Added to database: 07/16/2026, 23:03:52 UTC
Last enriched: 07/24/2026, 22:46:07 UTC
Last updated: 08/30/2026, 12:18:48 UTC
Views: 103
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.