Description
Netty QUIC codec is a QUIC codec for netty which makes use of quiche. An issue was discovered in the codec. A hash collision vulnerability (in the hash map used to manage connections) allows remote attackers to cause a considerable CPU load on the server (a Hash DoS attack) by initiating connections with colliding Source Connection IDs (SCIDs). This vulnerability is fixed in 0.0.71.Final.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-9052 | Netty QUIC codec is a QUIC codec for netty which makes use of quiche. An issue was discovered in the codec. A hash collision vulnerability (in the hash map used to manage connections) allows remote attackers to cause a considerable CPU load on the server (a Hash DoS attack) by initiating connections with colliding Source Connection IDs (SCIDs). This vulnerability is fixed in 0.0.71.Final. |
Github GHSA |
GHSA-hqqc-jr88-p6x2 | Netty QUIC hash collision DoS attack |
References
History
Tue, 01 Apr 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 31 Mar 2025 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Netty QUIC codec is a QUIC codec for netty which makes use of quiche. An issue was discovered in the codec. A hash collision vulnerability (in the hash map used to manage connections) allows remote attackers to cause a considerable CPU load on the server (a Hash DoS attack) by initiating connections with colliding Source Connection IDs (SCIDs). This vulnerability is fixed in 0.0.71.Final. | |
| Title | Netty QUIC hash collision DoS attack | |
| Weaknesses | CWE-407 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-04-01T13:50:43.647Z
Reserved: 2025-03-12T13:42:22.134Z
Link: CVE-2025-29908
Updated: 2025-03-31T21:08:50.363Z
Status : Awaiting Analysis
Published: 2025-03-31T19:15:40.367
Modified: 2025-04-01T20:26:22.890
Link: CVE-2025-29908
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA