s2n-quic Memory Exhaustion Vulnerability Requires Immediate Update
s2n-quic versions before 1.82.0 have a nasty memory leak vulnerability (CVE-2026-10740) that lets unauthenticated attackers crash your server. The CRYPTO frame reassembler doesn't cap memory allocation, so a single 1200-byte packet can gobble up 9.4 MB—spam a few and you're looking at denial of service. No handshake needed to exploit this. Action required: upgrade to v1.82.0 or later ASAP.
source: [aws/security-bulletin]