CVE-2026-35191: QUIC Unvalidated Amplification Credit may be Over Accounted

Published Sep 29, 2026
·
Updated

Issue summary: The OpenSSL QUIC server, when configured to not preform address validation, can be forced to count incoming packets multiple times in its unvalidated credit computation, leading to a violation of the RFC 9000 unvalidated connection amplification limit of 3 times the amount of data received.

Other sources

QUIC Unvalidated Amplification Credit may be Over Accounted

— Debian

Affected Software

2 affected componentsFixes available
OpenSSL OpenSSL
debian/openssl<=3.5.7-1~deb13u2, <=3.6.4-1
3.0.20-1~deb12u23.0.22-1~deb12u1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade debian/openssl to a version that resolves this vulnerability.

    Fixed in 3.0.20-1~deb12u2Fixed in 3.0.22-1~deb12u1

Event History

Sep 29, 2026
CVE Published
via MITRE·03:32 PM
Data Sourced
via MITRE·03:32 PM
DescriptionWeakness
Data Sourced
via NVD·04:17 PM
DescriptionWeakness
Data Sourced
via Ubuntu·07:45 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Launchpad·07:46 PM
Description
Data Sourced
via Debian·07:46 PM
DescriptionAffected Software

Frequently Asked Questions

1

Which deployments are exposed?

OpenSSL deployments using the QUIC stack as a server are affected only when client address validation has been disabled. The issue concerns the pre-handshake limit on traffic sent to an unvalidated peer address.

2

What does an attacker need to exploit this?

An attacker must be able to send spoofed packets to the affected QUIC server. The flaw can allow the server to send more than the RFC 9000 three-to-one amplification limit, making it usable in a DDoS amplification attack.

3

What can be done if updates cannot be applied immediately?

Enable client address validation on the QUIC server rather than operating in non-validation mode. The described accounting error occurs specifically when address validation is disabled.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203