Skip to content
CloudflareGHSA-78wx-jg4j-5j6g

Unlimited resource allocation by QUIC CRYPTO frames flooding

Medium5.9CVE-2024-1765 · Published Mar 12, 2024 · updated Jul 14, 2026

### Impact Cloudflare Quiche (through version 0.19.1/0.20.0) was affected by an unlimited resource allocation vulnerability causing rapid increase of memory usage of the system running quiche server or client. A remote attacker could take advantage of this vulnerability by repeatedly sending an unlimited number of 1-RTT CRYPTO frames after previously completing the QUIC handshake. Exploitation was possible for the duration of the connection which could be extended by the attacker. ### Patches quiche 0.19.2 and 0.20.1 are the earliest versions containing the fix for this issue.

GitHub advisory

Affected versions

PackageAffectedFixed in
quiche
crates.io
< 0.19.20.19.2
< 0.20.10.20.1
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-400, CWE-770

More Cloudflare advisories

All Cloudflare
Advisory
Unbounded storage of information related to connection ID retirement in quiche
Low3.7Mar 12, 2024
Information disclosure of Cloudflare API for low privileged users
High8.1Jan 29, 2024
Kyber: timing side-channel (kyberslash2)
HighJan 8, 2024
Arbitrary remote code execution within `wrangler dev` Workers sandbox
High8.5Dec 29, 2023
Arbitrary remote file read in Wrangler dev server
Medium6.9Dec 29, 2023
Server-Side Request Forgery (SSRF) in Miniflare
High8.0Dec 29, 2023

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.