CVE-2025-64702 affects quic-go versions 0.56.0 and below, allowing excessive memory allocation in its HTTP/3 client and server implementations. An attacker can trigger this by sending a QPACK-encoded HEADERS frame that, when decoded, results in a very large header field section, leading to memory exhaustion. This vulnerability has a CVSS score of 5.3 (Medium), indicating a low-complexity attack that can be executed remotely without authentication, resulting in a denial of service. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.57.0CPE matchmatch criteria | cpe:2.3:a:quic-go_project:quic-go:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.