Quic Go is a Go-language implementation of the QUIC protocol, a transport-layer standard increasingly used for web connectivity and real-time communication, with exposure centered on its WebTransport implementation. The vulnerability footprint for this vendor reflects the protocol-parsing and state-management complexity inherent to a modern transport implementation. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Quic Go over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-40898HIGH quic-go is an implementation of the QUIC protocol in Go. Prior to version 0.59.1, an attacker can cause excessive memory allocation in quic-go's HTTP/3 client and server implementa | Jun 4, 2026 | 7.5 | 31 | NO | NO |
CVE-2026-21435HIGH webtransport-go is an implementation of the WebTransport protocol. Prior to v0.10.0, an attacker can cause a denial of service in webtransport-go by preventing or indefinitely dela | Feb 12, 2026 | 7.5 | 25 | NO | NO |
CVE-2026-21434HIGH webtransport-go is an implementation of the WebTransport protocol. From 0.3.0 to 0.9.0, an attacker can cause excessive memory consumption in webtransport-go's session implementati | Feb 12, 2026 | 7.5 | 25 | NO | NO |
CVE-2022-30591HIGH quic-go through 0.27.0 allows remote attackers to cause a denial of service (CPU consumption) via a Slowloris variant in which incomplete QUIC or HTTP/3 requests are sent. This occ | Jul 6, 2022 | 7.5 | 25 | NO | NO |
CVE-2023-46239HIGH quic-go is an implementation of the QUIC protocol in Go. Starting in version 0.37.0 and prior to version 0.37.3, by serializing an ACK frame after the CRYTPO that allows a node to | Oct 31, 2023 | 7.5 | 22 | NO | NO |
CVE-2026-21438MEDIUM webtransport-go is an implementation of the WebTransport protocol. Prior to 0.10.0, an attacker can cause unbounded memory consumption repeatedly creating and closing many WebTrans | Feb 12, 2026 | 5.3 | 20 | NO | NO |
CVE-2025-64702MEDIUM quic-go is an implementation of the QUIC protocol in Go. Versions 0.56.0 and below are vulnerable to excessive memory allocation through quic-go's HTTP/3 client and server implemen | Dec 11, 2025 | 5.3 | 20 | NO | NO |
CVE-2023-49295MEDIUM quic-go is an implementation of the QUIC protocol (RFC 9000, RFC 9001, RFC 9002) in Go. An attacker can cause its peer to run out of memory sending a large number of PATH_CHALLENGE | Jan 10, 2024 | 6.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Quic Go.
Media articles that mention a CVE ID that affects a product developed by Quic Go — matched by CVE ID, not by vendor name.