quic-go
- Total products in the ecosystem
- 2
- Total vulnerabilities (90 days)
- 1
en
Verify to analyze this security profile
As of 09/20/2026, quic-go recorded 1 security vulnerabilities in the last 90 days across 1 products, including 0 rated High or above and 0 known exploited vulnerabilities (KEV) that should be prioritized for immediate remediation.
Over the last 90 days, webtransport-go had the most security vulnerabilities in the quic-go ecosystem, with 1 vulnerabilities—approximately 100% of the provider's total vulnerabilities during this period.
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan| Vulnerability | Exploitation status | Fix | Affected product | Published | Severity |
|---|---|---|---|---|---|
CVE-2026-57497webtransport-go: Memory Exhaustion Attack due to Buffering of Unknown Capsules | Exploitation statusNot known exploited | FixYes | Affected productwebtransport-go | Published09/14/2026 | SeverityMedium |
CVE-2026-40898quic-go: HTTP/3 QPACK Trailer Expansion Memory Exhaustion | Exploitation statusNot known exploited | FixNot confirmed | Affected productquic-go | Published06/04/2026 | SeverityMedium |
CVE-2026-21438webtransport-go affected by a Memory Exhaustion Attack due to Missing Cleanup of Streams Map | Exploitation statusNot known exploited | FixYes | Affected productwebtransport-go | Published02/12/2026 | SeverityMedium |
CVE-2026-21435webtransport-go CloseWithError can block indefinitely | Exploitation statusNot known exploited | FixYes | Affected productwebtransport-go | Published02/12/2026 | SeverityMedium |
CVE-2026-21434webtransport-go affected by Memory Exhaustion Attack due to Missing Length Check in WT_CLOSE_SESSION Capsule | Exploitation statusNot known exploited | FixYes | Affected productwebtransport-go | Published02/12/2026 | SeverityMedium |
CVE-2025-64702quic-go HTTP/3 QPACK Header Expansion DoS | Exploitation statusNot known exploited | FixYes | Affected productquic-go | Published12/11/2025 | SeverityMedium |
CVE-2025-59530quic-go has Client Crash Due to Premature HANDSHAKE_DONE Frame | Exploitation statusNot known exploited | FixNot confirmed | Affected productquic-go | Published10/10/2025 | SeverityHigh |
CVE-2025-29785quic-go Has Panic in Path Probe Loss Recovery Handling | Exploitation statusNot known exploited | FixNot confirmed | Affected productquic-go | Published06/02/2025 | SeverityHigh |
CVE-2024-53259quic-go affected by an ICMP Packet Too Large Injection Attack on Linux | Exploitation statusNot known exploited | FixYes | Affected productquic-go | Published12/02/2024 | SeverityMedium |
CVE-2024-22189QUIC's Connection ID Mechanism vulnerable to Memory Exhaustion Attack | Exploitation statusNot known exploited | FixNot confirmed | Affected productquic-go | Published04/04/2024 | SeverityHigh |
CVE-2023-49295quic-go's path validation mechanism can cause denial of service | Exploitation statusNot known exploited | FixYes | Affected productquic-go | Published01/10/2024 | SeverityMedium |
CVE-2023-46239quic-go vulnerable to pointer dereference that can lead to panic | Exploitation statusNot known exploited | FixNot confirmed | Affected productquic-go | Published10/31/2023 | SeverityHigh |