H2O Quicly Assertion Failure Vulnerability Leading to Denial-of-Service

Vulnerability

A denial-of-service vulnerability has been identified in H2O Quicly, an implementation of the IETF QUIC protocol. This issue arises from an assertion failure that occurs when the total number of valid handshake messages received over a CRYPTO stream within a single packet number space exceeds 32KB. The vulnerability is present in versions of Quicly prior to the commit 937d0e9.

Impact

Exceeding the CRYPTO stream limit causes an assertion failure, leading to a denial-of-service condition.

Reproduction

The vulnerability can be reproduced by sending a large number of valid handshake messages over a CRYPTO stream in a single packet number space, exceeding the 32KB limit. This can be done using a QUIC client that allows for manipulation of the handshake message size and stream data.

Remediation

Users can update to Quicly version 8b178e6 or later, where this vulnerability has been fixed.

Added: Jul 17, 2026, 12:42 AM
Updated: Jul 17, 2026, 12:42 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
8.4
remediation
0.0
relevance
9.6
threat
4.8
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.