openssl is vulnerable to Denial of Service (DoS)
37
Low Risk
After a QUIC handshake, OpenSSL stores metadata for acknowledgement only packets even though the peer does not have to acknowledge them. A peer that sends many frames that demand an acknowledgement, such as PING frames, and then withholds acknowledgements of later data, makes that metadata grow for the life of the connection and can exhaust memory across many connections. The fix records those transmissions in the packet history watermarks without storing the packet metadata.
You are affected if you are using a version that falls within the vulnerable range and your application completes OpenSSL QUIC handshakes with untrusted peers.
openssl is vulnerable to Denial of Service (DoS) in versions 3.4.0 - 3.4.6, 3.5.0 - 3.5.7, 3.6.0 - 3.6.3 and 4.0.0 - 4.0.1.
Upgrade the openssl library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.