CVE-2026-42772 is a vulnerability in OpenSSL
Published on September 29, 2026
Potential CPU DoS via O(n^2) Fragment Reassembly in QUIC
Issue summary: The QUIC stream reassembly algorithm performance deteriorates
progressively as packets are arriving out of order. The worst case has
a quadratic complexity proportional to the number of stream frames kept in
the buffer for the received stream data.
Impact summary: A remote QUIC peer that completes the handshake can create
a connection-scoped CPU pressure and potentially a Denial of Service using
compliant STREAM frames inside the advertised receive window, with low
attacker bandwidth.
CWE: CWE-407: Inefficient Algorithmic Complexity
Description: OpenSSL manages received QUIC stream fragments using a
doubly-linked list. While it optimizes for append operations (at the end of
the list), it falls back to a head-to-tail linear search for any fragment
that does not immediately follow the current `tail`.
By manipulating the sequence of offsets, an attacker can force the server
to perform O(n^2) operations, consuming excessive CPU time for the
QUIC process.
FIPS impact: no
The FIPS module is not affected as the QUIC implementation is outside of
the OpenSSL FIPS module boundary.
Weakness Type
Inefficient Algorithmic Complexity
An algorithm in a product has an inefficient worst-case computational complexity that may be detrimental to system performance and can be triggered by an attacker, typically using crafted manipulations that ensure that the worst case is being reached.
Products Associated with CVE-2026-42772
Want to know whenever a new CVE is published for OpenSSL? stack.watch will email you.
Affected Versions
OpenSSL:- Version 4.0.0 and below 4.0.3 is affected.
- Version 3.6.0 and below 3.6.5 is affected.
- Version 3.5.0 and below 3.5.9 is affected.
- Version 3.4.0 and below 3.4.8 is affected.