Impact
The vulnerability exists in webtransport-go versions before 0.11.1. In those releases, Session.parseNextCapsule() skips unknown WebTransport capsules by reading the entire declared capsule body into memory with io.ReadAll before discarding it. A malicious peer can therefore send an arbitrarily large unknown capsule, causing the client or server to allocate memory for the full payload. Because QUIC flow control advances independently of the cached data, no bound limits the retained allocation, leading to unchecked memory growth that can disrupt or crash the v0.11.1.
Affected Systems
The issue affects the webtransport-go implementation from quic-go, specifically any version before 0.11.1. Both client and server sides that use the unpatched library are vulnerable. Users should confirm the version of the library in use and apply a fix if it falls within the affected range.
Risk and Exploitability
The CVSS score of 5.3 classifies the vulnerability as medium severity. The EPSS score of <1% indicates a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, further suggesting limited known exploitation. An attacker can exploit this remotely by sending an HTTP/3 request containing a large unknown capsule; no local privileges, authentication, or additional dependencies are required. Since the capsule is accepted and fully buffered before being discarded, a single unauthenticated connection can trigger memory exhaustion, potentially disrupting the service.
OpenCVE Enrichment
Github GHSA