Netty QUIC hash collision DoS attack
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 5.3epss 0.5%
exploitation probability
0.5%top 57% of all CVEs
observed exploitation
nono source reports it
In short
Netty's QUIC codec can be overwhelmed by an attacker sending specially crafted connection requests with identical hash values, causing the server to waste CPU resources and become slow or unresponsive.
Technical detail
A hash collision vulnerability in the connection management hash map of Netty QUIC codec allows remote attackers to trigger excessive CPU consumption through crafted Source Connection IDs (SCIDs). The attack requires no authentication and exploits poor hash distribution, resulting in denial of service.
Summary generated and translated by AI from the official description.
Netty QUIC codec is a QUIC codec for netty which makes use of quiche. An issue was discovered in the codec. A hash collision vulnerability (in the hash map used to manage connections) allows remote attackers to cause a considerable CPU load on the server (a Hash DoS attack) by initiating connections with colliding Source Connection IDs (SCIDs). This vulnerability is fixed in 0.0.71.Final.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Affected products
netty · netty-incubator-codec-quic