CVE-2026-44433: Quicly is an IETF QUIC protocol implementation intended primarily for use within the H2O HTTP server. Prior to commit 8b
Summary
Quicly is a library that implements the QUIC protocol (a modern internet communication standard) for the H2O web server. Before a certain code update, an attacker could send specially crafted network messages that trick the server into allocating huge amounts of memory using very few packets, potentially causing a denial of service (making the service unavailable by exhausting its resources).
Solution / Mitigation
This issue has been fixed by commit 8b178e6.
Vulnerability Details
5.3(medium)
EPSS: 0.0%
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
network
low
none
none
July 16, 2026
Classification
Affected Vendors
Related Issues
CVE-2026-47482: NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause missing release of memory
CVE-2022-29200: TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the implem
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-44433
First tracked: July 17, 2026 at 02:08 AM
Classified by LLM (prompt v3) · confidence: 65%