CVE-2025-61684

Quicly, an IETF QUIC protocol implementation, is susceptible to a denial-of-service attack prior to commit d9d3df6a8530a102b57d840e39b0311ce5c9e14e. A remote attacker can exploit these bugs to trigger an assertion failure that crashes process using Quicly. Commit d9d3df6a8530a102b57d840e39b0311ce5c9e14e fixes the issue.
Configurations

Configuration 1 (hide)

cpe:2.3:a:h2o:quicly:*:*:*:*:*:*:*:*

History

17 Jun 2026, 09:50

Type Values Removed Values Added
Summary
  • (es) Quicly, una implementación del protocolo QUIC de IETF, es susceptible a un ataque de denegación de servicio anterior al commit d9d3df6a8530a102b57d840e39b0311ce5c9e14e. Un atacante remoto puede explotar estos errores para desencadenar un fallo de aserción que bloquea el proceso que usa Quicly. El commit d9d3df6a8530a102b57d840e39b0311ce5c9e14e soluciona el problema.

27 Feb 2026, 19:41

Type Values Removed Values Added
CPE cpe:2.3:a:h2o:quicly:*:*:*:*:*:*:*:*
References () https://github.com/h2o/quicly/commit/d9d3df6a8530a102b57d840e39b0311ce5c9e14e - () https://github.com/h2o/quicly/commit/d9d3df6a8530a102b57d840e39b0311ce5c9e14e - Patch
References () https://github.com/h2o/quicly/security/advisories/GHSA-wr3c-345m-43v9 - () https://github.com/h2o/quicly/security/advisories/GHSA-wr3c-345m-43v9 - Vendor Advisory
CWE CWE-617
First Time H2o quicly
H2o

19 Jan 2026, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-19 16:15

Updated : 2026-06-17 09:50


NVD link : CVE-2025-61684

Mitre link : CVE-2025-61684

CVE.ORG link : CVE-2025-61684


JSON object : View

Products Affected

h2o

  • quicly
CWE
CWE-20

Improper Input Validation

CWE-617

Reachable Assertion