Intel

AIKIDO-2025-10180

github.com/quic-go/quic-go is vulnerable to Uncaught Exception

Uncaught ExceptionCVE-2025-29785 Published Mar 25, 2025

18

Low Risk

This Affects:

GOgithub.com/quic-go/quic-go
0.50.0 - 0.50.0
Fixed in 0.50.1
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to uncaught exceptions due to a flaw in the probe packet tracking logic. Under specific loss and acknowledgment patterns, this can result in a nil-pointer dereference, potentially causing unexpected crashes and disrupting application stability.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

github.com/quic-go/quic-go is vulnerable to Uncaught Exception in versions 0.50.0 - 0.50.0.

How to fix this

Upgrade the github.com/quic-go/quic-go library to the patch version.