Executive brief
Quicly is a software library used by the H2O web server to handle modern internet traffic. A flaw in how it processes encrypted handshake messages allows a remote attacker to crash the server by sending a specific sequence of data. This results in a denial-of-service, making the website or service unavailable to legitimate users.
Technical details
A reachable assertion vulnerability exists in Quicly's handling of CRYPTO streams. The software triggers an assertion failure (CWE-617) when it receives more than 32KB of valid handshake messages within a single packet number space. This occurs due to uncontrolled resource consumption (CWE-400) during the QUIC handshake process. An unauthenticated remote attacker can exploit this by sending a large volume of handshake data, leading to an immediate process crash and denial of service. The issue is resolved in commit 937d0e9.
Affected products
- h2o quicly Prior to commit 937d0e9
Timeline
- 2026-05-29: advisory: GitHub Security Advisory published
- 2026-07-16: disclosed: CVE published to NVD