VendorsQuic-go Projectquic-goany version
Vulnerabilities

Quic-go Project Quic-go any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2022-30591
quic-go through 0.27.0 allows remote attackers to cause a denial of service (CPU consumption) via a Slowloris variant in which incomplete QUIC or HTTP/3 requests are sent. This occurs because mtu_discoverer.go misparses the MTU Discovery service and consequently overflows the probe timer. NOTE: the vendor's position is that this behavior should not be listed as a vulnerability on the CVE List
Published 2022-07-06 · Modified
7.5EPSS 0.029
CVE-2023-46239
quic-go vulnerable to pointer dereference that can lead to panic
Published 2023-10-31 · Modified
7.5EPSS 0.008
CVE-2026-40898
quic-go: HTTP/3 QPACK Trailer Expansion Memory Exhaustion
Published 2026-06-04 · Analyzed
7.5EPSS 0.005
CVE-2023-49295
quic-go's path validation mechanism can cause denial of service
Published 2024-01-10 · Modified
6.5EPSS 0.012
CVE-2025-64702
quic-go HTTP/3 QPACK Header Expansion DoS
Published 2025-12-11 · Analyzed
5.3EPSS 0.004