s2nQUIC (<1.89) DOS via crafted UDP DCI length
CVE-2026-94450 Published on September 22, 2026
Potential denial of service when configured to send Retry packets in s2n-quic
Improper validation of the Destination Connection ID length in s2n-quic 1.88.0 and earlier may allow an unauthenticated remote user to cause a denial of service by shutting down a server endpoint via a single crafted UDP datagram. Only server endpoints specifically configured to send Retry packets are affected.
To remediate this issue, users should upgrade to version v1.89.0 or later.
Vulnerability Analysis
CVE-2026-94450 is exploitable with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity, and a high impact on availability.
Weakness Type
Improper Validation of Specified Quantity in Input
The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties.
Products Associated with CVE-2026-94450
Want to know whenever a new CVE is published for Aws S2n Quic? stack.watch will email you.
Affected Versions
AWS s2n-quic:- Before and including 1.88.0 is affected.