bartek@aws: ~/news
$ whoami
$ AWS Architect · DevOps · Cloud

tag: s2n-quic

show all
Thursday, August 20, 2026

s2n-quic Memory Exhaustion Vulnerability Requires Immediate Update

s2n-quic versions before 1.82.0 have a nasty memory leak vulnerability (CVE-2026-10740) that lets unauthenticated attackers crash your server. The CRYPTO frame reassembler doesn't cap memory allocation, so a single 1200-byte packet can gobble up 9.4 MB—spam a few and you're looking at denial of service. No handshake needed to exploit this. Action required: upgrade to v1.82.0 or later ASAP.

source: [aws/security-bulletin]