/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CVE-2023-39322

Published

Last updated

NVD

https://nvd.nist.gov/vuln/detail/CVE-2023-39322

Severity

7.5

High

CVSS V3

Description

QUIC connections do not set an upper bound on the amount of data buffered when reading post-handshake messages, allowing a malicious QUIC connection to cause unbounded memory growth. With fix, connections now consistently reject messages larger than 65KiB in size.

References

Affected packages


The trusted source for open source

Talk to an expert
© 2025 Chainguard. All Rights Reserved.
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing