SEPTEMBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-44435

HIGH · CVSS 7.5 EPSS 0.28% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-16 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

An assertion failure in the Quicly implementation of the QUIC protocol can lead to a Denial of Service when more than 32KB of valid handshake messages are received over a single packet number space. This vulnerability primarily affects users of the H2O HTTP server utilizing Quicly. Organizations relying on this server should prioritize patching to mitigate potential service disruptions.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-44435
Severity
HIGH
CVSS
7.5
EPSS
0.28%

Original NVD Description

Quicly is an IETF QUIC protocol implementation intended primarily for use within the H2O HTTP server. Prior to commit 937d0e9, an assertion failure is raised when the total number of valid handshake messages received over a CRYPTO stream of a single packet number space exceeds 32KB, causing a Denial of Service. This issue has been fixed by commit 937d0e9.

Related CVEs

Other vulnerabilities affecting the same vendor(s)