Description
QTI Neon is a minimal, game-agnostic, relay-based UDP multiplayer protocol library. In version 1.0.0, the relay's handleReconnectRequest forwards RECONNECT_REQUEST packets to the host without bounding them, so an unauthenticated client can drive relay-to-host amplification and cause a denial of service on the host. No fixed version is available as of this review.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-85rg-p3fr-xc2f | QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding |
References
History
Tue, 28 Jul 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 28 Jul 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | QTI Neon is a minimal, game-agnostic, relay-based UDP multiplayer protocol library. In version 1.0.0, the relay's handleReconnectRequest forwards RECONNECT_REQUEST packets to the host without bounding them, so an unauthenticated client can drive relay-to-host amplification and cause a denial of service on the host. No fixed version is available as of this review. | |
| Title | QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding | |
| Weaknesses | CWE-400 CWE-406 CWE-770 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-07-28T17:07:15.080Z
Reserved: 2026-06-15T19:45:23.540Z
Link: CVE-2026-54609
Updated: 2026-07-28T17:06:56.770Z
No data.
No data.
OpenCVE Enrichment
No data.
Github GHSA