Unlimited resource allocation by QUIC CRYPTO frames flooding
Medium5.9CVE-2024-1765 · Published Mar 12, 2024 · updated Jul 14, 2026
### Impact Cloudflare Quiche (through version 0.19.1/0.20.0) was affected by an unlimited resource allocation vulnerability causing rapid increase of memory usage of the system running quiche server or client. A remote attacker could take advantage of this vulnerability by repeatedly sending an unlimited number of 1-RTT CRYPTO frames after previously completing the QUIC handshake. Exploitation was possible for the duration of the connection which could be extended by the attacker. ### Patches quiche 0.19.2 and 0.20.1 are the earliest versions containing the fix for this issue.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| quiche crates.io | < 0.19.2 | 0.19.2 |
| < 0.20.1 | 0.20.1 |
Details and references
More Cloudflare advisories
All Cloudflare| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Mar 122024 | Unbounded storage of information related to connection ID retirement in quiche | Low3.7 | 0.19.2+1 more |
| Jan 292024 | Information disclosure of Cloudflare API for low privileged users | High8.1 | 4.12.3 |
| Jan 82024 | Kyber: timing side-channel (kyberslash2) | High | 1.3.7 |
| Dec 292023 | Arbitrary remote code execution within `wrangler dev` Workers sandbox | High8.5 | 3.19.0+1 more |
| Dec 292023 | Arbitrary remote file read in Wrangler dev server | Medium6.9 | 3.19.0 |
| Dec 292023 | Server-Side Request Forgery (SSRF) in Miniflare | High8.0 | 3.20231030.2 |