#VU109895 Inefficient Algorithmic Complexity in netty-incubator-codec-quic - CVE-2025-29908
Published: May 28, 2025
netty-incubator-codec-quic
Netty project
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a hash collision vulnerability in the hash map used to manage connections. A remote attacker can cause a considerable CPU load on the server (a Hash DoS attack) by initiating connections with colliding Source Connection IDs (SCIDs)