Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-34183

36
FAUCET Score

Issue summary: Remote peer may exhaust heap memory of the QUIC server or client by flooding it with packets containing PATH_CHALLENGE frames. Impact summary: A malicious remote peer can cause an unbounded memory allocation which can lead to an abnormal termination of the application acting as a QUIC client or server and a Denial of Service. A remote peer may exhaust heap memory by flooding the local QUIC stack with PATH_CHALLENGE frames. The local QUIC stack allocates a PATH_RESPONSE frame for every PATH_CHALLENGE it receives. The allocated PATH_RESPONSE frame gets freed only when the remote peer acknowledges reception of the PATH_RESPONSE frame which will not be done by a malicious peer. The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this issue. The QUIC stack is outside of OpenSSL FIPS module boundary.

First published: Jun 9, 2026Last modified: Jun 10, 2026

Impacted Technologies

VendorProductVersion(s)CPE
>= 3.4.0, < 3.4.6CPE matchmatch criteria
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*
>= 3.5.0, < 3.5.7CPE matchmatch criteria
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*
>= 3.6.0, < 3.6.3CPE matchmatch criteria
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*
4.0.0CPE matchmatch criteria
cpe:2.3:a:openssl:openssl:4.0.0:-:*:*:*:*:*:*
>= 4.0.0, < 4.0.1CPE match
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.05%
Probability of exploitation in next 30 days
EPSS Percentile
60.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0105 is in the 37th percentile among its peer group of 51,506 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (7)

github_advisorypatch availablevia nvd_reference
View patch
microsoftpatch availablevia msrc
Product: azl3 openssl 3.3.5-5 on Azure Linux 3.0Fixed in: 3.3.7-3
microsoftpatch availablevia msrc
Product: 21264-17084Fixed in: 3.3.7-3
ubuntupatch availablevia ubuntu_usn
Product: openssl (resolute)Fixed in: 3.5.5-1ubuntu3.2
ubuntupatch availablevia ubuntu_usn
Product: openssl (questing)Fixed in: 3.5.3-1ubuntu3.4
ubuntupatch availablevia ubuntu_usn
Product: openssl (jammy)Fixed in: 3.0.2-0ubuntu1.25
ubuntupatch availablevia ubuntu_usn
Product: openssl (noble)Fixed in: 3.0.13-0ubuntu3.11

Vendor Advisories (2)

ubuntuUSN-8414-1

OpenSSL vulnerabilities

Jun 9, 2026
microsoft2026-Jun/CVE-2026-34183Important

Unbounded Memory Growth in the QUIC PATH_CHALLENGE Handler

Jun 9, 2026

References

github.com / openssl/openssl/commit/5b306efb0b3779dfdd0803b4afc9d08c91f11517
Patch
github.com / openssl/openssl/commit/7d06955ebe0ecf8adfd4c1e92018586da47ef9ac
Patch
github.com / openssl/openssl/commit/d2e9efbe4900a373227deb136e8665401404ffac
Patch
github.com / openssl/openssl/commit/fbaa83859c01ad64f497b757aaf51be7d05ed9eb
Patch
openssl-library.org / news/secadv/20260609.txt
Vendor Advisory