The Quic Go Project maintains a focused, single-product implementation of the QUIC protocol in Go, which despite its narrow scope has achieved prominence as a protocol library used across a range of applications and services. Observed vulnerabilities center on the protocol implementation itself; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Quic Go Project over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-40898HIGH quic-go is an implementation of the QUIC protocol in Go. Prior to version 0.59.1, an attacker can cause excessive memory allocation in quic-go's HTTP/3 client and server implementa | Jun 4, 2026 | 7.5 | 31 | NO | NO |
CVE-2026-21435HIGH webtransport-go is an implementation of the WebTransport protocol. Prior to v0.10.0, an attacker can cause a denial of service in webtransport-go by preventing or indefinitely dela | Feb 12, 2026 | 7.5 | 25 | NO | NO |
CVE-2026-21434HIGH webtransport-go is an implementation of the WebTransport protocol. From 0.3.0 to 0.9.0, an attacker can cause excessive memory consumption in webtransport-go's session implementati | Feb 12, 2026 | 7.5 | 25 | NO | NO |
CVE-2022-30591HIGH quic-go through 0.27.0 allows remote attackers to cause a denial of service (CPU consumption) via a Slowloris variant in which incomplete QUIC or HTTP/3 requests are sent. This occ | Jul 6, 2022 | 7.5 | 25 | NO | NO |
CVE-2023-46239HIGH quic-go is an implementation of the QUIC protocol in Go. Starting in version 0.37.0 and prior to version 0.37.3, by serializing an ACK frame after the CRYTPO that allows a node to | Oct 31, 2023 | 7.5 | 22 | NO | NO |
CVE-2026-21438MEDIUM webtransport-go is an implementation of the WebTransport protocol. Prior to 0.10.0, an attacker can cause unbounded memory consumption repeatedly creating and closing many WebTrans | Feb 12, 2026 | 5.3 | 20 | NO | NO |
CVE-2025-64702MEDIUM quic-go is an implementation of the QUIC protocol in Go. Versions 0.56.0 and below are vulnerable to excessive memory allocation through quic-go's HTTP/3 client and server implemen | Dec 11, 2025 | 5.3 | 20 | NO | NO |
CVE-2023-49295MEDIUM quic-go is an implementation of the QUIC protocol (RFC 9000, RFC 9001, RFC 9002) in Go. An attacker can cause its peer to run out of memory sending a large number of PATH_CHALLENGE | Jan 10, 2024 | 6.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Quic Go Project.
Media articles that mention a CVE ID that affects a product developed by Quic Go Project — matched by CVE ID, not by vendor name.