CVE-2026-10740
Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
10/06/2026
Last modified:
10/06/2026
Description
Unbounded memory allocation in the CRYPTO frame reassembler in s2n-quic before 1.8.2 may allow an unauthenticated remote actor to cause a denial of service (degraded availability) by sending crafted QUIC Initial packets.<br />
<br />
<br />
<br />
To remediate this issue, users should upgrade to v1.8.2.
Impact
Base Score 4.0
6.90
Severity 4.0
MEDIUM
Base Score 3.x
5.30
Severity 3.x
MEDIUM



