Uncaught Exception in quic-go - CVE-2025-29785
Published: April 25, 2026
quic-go
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an uncaught exception in the loss recovery logic for path probe packets when handling specially crafted ACKs for server-sent packets during path validation. A remote attacker can send valid QUIC packets from different remote addresses and then send specially crafted ACKs to cause a denial of service.