{"id":"CVE-2026-10740","aliases":["GHSA-9q54-f358-3fqf"],"url":"https://o3.security/vulnerability/CVE-2026-10740","summary":"Excessive memory allocation in s2n-quic","details":"s2n-quic is a Rust implementation of the QUIC protocol. An unauthenticated user can attempt to exhaust server memory on an s2n-quic endpoint by sending crafted CRYPTO frames with high offsets. The buffer used for processing CRYPTO frames does not enforce a maximum size. In the worst case, a single 1200-byte packet can cause approximately 9.4 MB of allocation. By repeatedly sending such packets, the resulting memory pressure could cause denial of service. No valid handshake is required.\n\nImpacted versions: <= v1.81.0\n\n### Patches\nThis issue has been addressed in s2n-quic version v1.82.0. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. \n\n### Workarounds\nThere is no workaround that fully mitigates this issue. Upgrading to the patched version is the recommended remediation.\n\n### References\nIf there are any questions or comments about this advisory, contact AWS Security via the [vulnerability reporting page](https://aws.amazon.com/security/vulnerability-reporting) or directly via email to [aws-security@amazon.com](mailto:aws-security@amazon.com). Please do not create a public GitHub issue.","published":"2026-06-10T18:09:36.070Z","modified":"2026-08-12T03:51:28.486053580Z","cvss":null,"epss":{"score":0.00291,"percentile":0.2182,"asOf":"2026-09-17"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"crates.io","name":"s2n-quic","fixedVersion":"1.82.0"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://aws.amazon.com/security/security-bulletins/2026-042-aws/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/10xxx/CVE-2026-10740.json"},{"type":"ADVISORY","url":"https://github.com/aws/s2n-quic/security/advisories/GHSA-9q54-f358-3fqf"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-10740"},{"type":"FIX","url":"https://github.com/aws/s2n-quic/releases/tag/v1.82.0"},{"type":"WEB","url":"https://aws.amazon.com/security/security-bulletins/2026-042-aws"},{"type":"PACKAGE","url":"https://github.com/aws/s2n-quic"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:28.486053580Z"}}