Junglewise Threat Intelligence

CVE-2026-40898: quic-go memory exhaustion in HTTP/3 trailers

CVE-2026-40898 · Severity: medium · CVSS 5.3 · Published 2026-06-04

Technologies: github.com/quic-go/quic-go (Go). Vendors: Go.

Executive brief

A vulnerability in the quic-go library, which provides QUIC and HTTP/3 networking capabilities for Go applications, can allow an attacker to crash a server or client. By sending specially crafted HTTP/3 trailers, a malicious user can force the application to consume excessive amounts of memory. This results in a denial-of-service (DoS) condition, potentially disrupting business operations and service availability.

Technical details

A resource exhaustion vulnerability exists in quic-go's HTTP/3 implementation due to improper validation of decoded field section sizes in QPACK-encoded HEADERS frames used for trailers. While the library enforced limits on the size of compressed frames, it failed to limit the size of the decoded field section. An attacker can exploit this by sending a crafted HEADERS frame that expands significantly upon decoding (up to 50x), leading to excessive memory allocation in both client and server implementations. This issue is addressed in version 0.59.1 by implementing incremental decoding and enforcing RFC 9114 size limits for trailers.

Affected products

  • quic-go quic-go <= v0.59.0

Timeline

  • 2026-05-11: patched: Version 0.59.1 released
  • 2026-05-31: advisory: GitHub Security Advisory published
  • 2026-06-04: disclosed: CVE-2026-40898 published to NVD

References

Related threats