Quicly QUIC Protocol Implementation Stateless Reset Injection Vulnerability

Vulnerability

A vulnerability allowing stateless reset injection has been identified in Quicly, an IETF QUIC protocol implementation primarily used within the H2O HTTP server. This issue arises from inadequate validation of packet entries, enabling on-path attackers to reset QUIC connections managed by Quicly. The vulnerability affects Quicly versions prior to the commit dccf5d4.

Impact

Exploitation of this vulnerability allows an on-path attacker to reset QUIC connections governed by Quicly, disrupting the communication flow.

Reproduction

The vulnerability can be reproduced by sending a QUIC packet that ends with 16 zero bytes. Quicly misinterprets this as a stateless reset, causing the connection to be reset. This can be automated with a script that sends such a packet after the QUIC handshake is completed.

Remediation

Users can update to Quicly commit 8b178e6 or later, where this vulnerability has been fixed.

Added: Jul 17, 2026, 12:47 AM
Updated: Jul 17, 2026, 12:47 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
7.2
remediation
0.0
relevance
9.7
threat
4.8
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.