Expected behavior violation in OpenSSL - CVE-2026-35191
Published: September 30, 2026
Vulnerability details
The vulnerability allows a remote attacker to amplify a distributed denial-of-service attack.
The vulnerability exists due to an expected behavior violation in the QUIC server unvalidated credit computation when processing a datagram containing multiple QUIC packets. A remote attacker can send a multi-packet QUIC datagram to amplify a distributed denial-of-service attack.
The server must be configured without client address validation.
Affected software
Debian Linux
openssl (Debian package)
How to mitigate CVE-2026-35191
openssl (Debian package) - update to 3.5.7-1~deb13u3