Allocation of Resources Without Limits or Throttling in OpenSSL - CVE-2026-54873

 

Allocation of Resources Without Limits or Throttling in OpenSSL - CVE-2026-54873

Published: September 30, 2026


Vulnerability identifier: #VU152957
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-54873
CWE-ID: CWE-770
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to allocation of resources without limits or throttling in QUIC stream fragment metadata handling when stream data remains in packet buffers pending application reads. A remote attacker can send crafted QUIC packets to cause a denial of service.

Packet-buffer retention time is controlled by the remote peer.


Affected software

OpenSSL
Debian Linux
openssl (Debian package)

How to mitigate CVE-2026-54873

Install security update from vendor's website.

OpenSSL - addressed in versions 1.0.2zs, 1.1.1zj, 3.0.23, 3.4.8, 3.5.9, 3.6.5, 4.0.3
openssl (Debian package) - update to 3.5.7-1~deb13u3

External References

Related Security Bulletins