Cloudflare Quiche Congestion Control Vulnerability Allowing Excessive Data Transmission

Vulnerability

A vulnerability in Cloudflare Quiche versions prior to 0.24.4 allows for incorrect growth of the congestion window. This flaw can lead to data being sent faster than the actual capacity of the network path. An unauthenticated remote attacker can exploit this by completing a handshake and starting a congestion-controlled data transfer. The attacker can then manipulate the victim's congestion control state by sending ACK frames, taking advantage of an opportunistic ACK attack as described in RFC 9000 Section 21.4. This manipulation can cause the victim to exceed normal congestion window limits, allowing more bytes in flight than the path can reliably support.

Impact

Exploitation of this vulnerability can disrupt normal data transmission rates, causing potential congestion and inefficiencies in network communication.

Remediation

Users can upgrade to Cloudflare Quiche version 0.24.4 or later to address this vulnerability.

Added: Sep 1, 2025, 7:22 PM
Updated: Sep 1, 2025, 7:22 PM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
2.5
exploitability
6.2
remediation
7.7
relevance
0.2
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.