Intel

AIKIDO-2026-956980

openssl is vulnerable to Denial of Service (DoS)

Denial of Service (DoS)CVE-2026-14456 Published 6 days ago

37

Low Risk

This Affects:

C++openssl
3.5.0 - 3.5.7
Fixed in 3.5.8
3.6.0 - 3.6.3
Fixed in 3.6.4
4.0.0 - 4.0.1
Fixed in 4.0.2
Are you affected? Scan for Free

TL;DR

An OpenSSL QUIC listener allocates a new channel for each valid Initial packet whose destination connection ID is unknown, and queues it until the application calls SSL_accept(). Nothing caps that queue, so a peer that sends Initial packets faster than the application accepts them can grow memory without a bound and make the listener unavailable. The fix limits pending channels, with a default of 256.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and your application accepts OpenSSL QUIC connections.

Background info

openssl is vulnerable to Denial of Service (DoS) in versions 3.5.0 - 3.5.7, 3.6.0 - 3.6.3 and 4.0.0 - 4.0.1.

How to fix this

Upgrade the openssl library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform