Skip to content
CloudflareGHSA-4q5x-gp38-rfp4

Unbounded path event queue growth via peer-driven source connection ID rotation

High7.5CVE-2026-12707 · Published Jul 14, 2026

Cloudflare quiche was discovered to be vulnerable to memory resource exhaustion due to unbounded queuing of post-handshake client migration events. quiche supports the connection migration features described in Section 9 of RFC 9000, which allows a single QUIC connection to survive changes in the network path. Although quiche implements the protections described in Section 9.3 of RFC 9000 to limit server state commitment, it was discovered that the collection of PathEvents, intended to be consumed by applications via the path_event_next() function, was not bounded.. Once the QUIC handshake completed, a peer could exploit rapid source address migration in order to cause unbounded queuing of the PathEvent::ReusedSourceConnectionId type. Servers are vulnerable even if active connection migration is disabled. quiche 0.29.3 is the earliest version containing the fix for this issue.

GitHub advisory

Affected versions

PackageAffectedFixed in
quiche
crates.io
>= 0.15.0, < 0.29.30.29.3
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Severity from
GitHub (reviewed advisory)

More Cloudflare advisories

All Cloudflare
Advisory
https://github.com/cloudflare/pages-action: remote code execution
High8.8Aug 12
Resource exhaustion in HTTP/3 and QPACK
High7.5Jul 14
Cloudflare Universal SSL: protection mechanism failure
High7.6Jul 1
Use-after-free in connection ID iterator FFI functions
Medium5.6Jun 19
Cache poisoning via insecure-by-default cache key
High8.4Mar 5
HTTP Request Smuggling via HTTP/1.0 and Transfer-Encoding Misparsing
Critical9.3Mar 5

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.