Junglewise Threat Intelligence

CVE-2026-94450: Amazon s2n-quic improper validation in Destination Connection ID

CVE-2026-94450 · Severity: high · CVSS 7.5 · Published 2026-09-22

Vendors: Amazon.

Executive brief

s2n-quic is a QUIC protocol implementation used in network communication libraries. An attacker can send a single malformed network packet to crash server endpoints configured to send Retry packets, causing a denial of service. The vulnerability only affects servers with specific Retry packet configuration enabled.

Technical details

Improper validation of the Destination Connection ID length in QUIC packet processing allows unauthenticated remote attackers to trigger a denial of service condition. The vulnerability affects server endpoints specifically configured to issue Retry packets, exploitable via a crafted UDP datagram with no authentication or user interaction required. A fix is available in version 1.89.0 and later.

Affected products

  • Amazon s2n-quic 1.88.0 and earlier

Timeline

  • 2026-09-22: disclosed
  • 2026-09-22: patched: version 1.89.0 released

References