Junglewise Threat Intelligence

CVE-2026-44435: H2O Quicly assertion failure in CRYPTO stream handling

CVE-2026-44435 · Severity: high · CVSS 7.5 · Published 2026-07-16

Technologies: H2o Quicly. Vendors: H2o.

Executive brief

Quicly is a software library used by the H2O web server to handle modern internet traffic. A flaw in how it processes encrypted handshake messages allows a remote attacker to crash the server by sending a specific sequence of data. This results in a denial-of-service, making the website or service unavailable to legitimate users.

Technical details

A reachable assertion vulnerability exists in Quicly's handling of CRYPTO streams. The software triggers an assertion failure (CWE-617) when it receives more than 32KB of valid handshake messages within a single packet number space. This occurs due to uncontrolled resource consumption (CWE-400) during the QUIC handshake process. An unauthenticated remote attacker can exploit this by sending a large volume of handshake data, leading to an immediate process crash and denial of service. The issue is resolved in commit 937d0e9.

Affected products

  • h2o quicly Prior to commit 937d0e9

Timeline

  • 2026-05-29: advisory: GitHub Security Advisory published
  • 2026-07-16: disclosed: CVE published to NVD

References

Related threats