Junglewise Threat Intelligence

CVE-2026-10740: AWS s2n-quic unbounded memory allocation in CRYPTO frame reassembler

CVE-2026-10740 · Severity: high · CVSS 5.3 · Published 2026-06-10

Technologies: Amazon AWS, s2n-quic (crates.io). Vendors: AWS, Amazon, crates.io.

Executive brief

AWS s2n-quic is a QUIC protocol implementation used in AWS services and customer applications. An excessive memory allocation vulnerability could allow an attacker to consume memory resources on systems running the library, potentially causing denial of service and service unavailability.

Technical details

This vulnerability involves excessive memory allocation in s2n-quic, the AWS QUIC protocol implementation. An attacker can exploit the memory allocation flaw through network-based attacks to cause denial of service by exhausting memory resources. The vulnerability is reachable over the network to any system running the affected s2n-quic library. No evidence of active exploitation in the wild has been reported. Patches or mitigations are available from AWS.

Affected products

  • AWS s2n-quic

Timeline

  • 2026-09-22: disclosed

References

Related threats