s2n-quic Denial of Service Vulnerability (CVE-2026-94450)
s2n-quic versions 1.88.0 and earlier have a vulnerability allowing unauthenticated attackers to crash server endpoints via a single crafted UDP packet. Only servers configured to send Retry packets are affected. AWS services aren't impacted, so AWS customers need no action. If you're running s2n-quic with Retry packets enabled, upgrade to the patched version immediately.
source: [aws/security-bulletin]