lucas-clemente quic-go
cpe:2.3:a:quic-go_project:quic-go:*:*:*:*:*:*:*
- <= 0.27.0
A denial-of-service vulnerability has been identified in quic-go versions through 0.27.0. This issue allows remote attackers to cause excessive CPU consumption by sending incomplete QUIC or HTTP/3 requests, exploiting a Slowloris-like technique. The vulnerability arises from a misinterpretation of the MTU Discovery service in the file mtu_discoverer.go, leading to an overflow of the probe timer.
Exploitation of this vulnerability causes increased CPU usage, potentially leading to performance degradation or service disruption.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.