A AegiFlow
MEDIUMCVSS 6.9EPSS 0.3%

CVE-2026-10740

s2n-quic has excessive memory allocation

Published
2026-08-14
Modified
2026-08-14
EPSS percentile
22%
Aliases
GHSA-9q54-f358-3fqf
Sources
github-advisory

Summary

s2n-quic is a Rust implementation of the QUIC protocol. An unauthenticated user can attempt to exhaust server memory on an s2n-quic endpoint by sending crafted CRYPTO frames with high offsets. The buffer used for processing CRYPTO frames does not enforce a maximum size. In the worst case, a single 1200-byte packet can cause approximately 9.4 MB of allocation. By repeatedly sending such packets, the resulting memory pressure could cause denial of service. No valid handshake is required. Impacted versions: <= v1.81.0 ### Patches This issue has been addressed in s2n-quic version v1.82.0. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. ### Workarounds There is no workaround that fully mitigates this issue. Upgrading to the patched version is the recommended remediation. ### References If there are any questions or comments about this advisory, contact AWS Security via the [vulnerability reporting page](https://aws.amazon.com/security/vulnerability-reporting) or directly via email to [[email protected]](mailto:[email protected]). Please do not create a public GitHub issue.

Affected packages

EcosystemPackageAffected versionsFixed versions
rusts2n-quic1.82.0

Remediation: Upgrade to 1.82.0 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.