Aller au contenu principal
HIGH

CVE-2026-18798

CVSS v3

7.5

HIGH

Score EPSS

1.5 %

probabilité d’exploitation

CISA KEV

Non

exploitation connue

Exploitation

statut SSVC

Description

Issue summary: QUIC server may double free QRX (QUIC record layer RX) object when channel creation fails for initial packet. Impact summary: Double free leads to heap corruption, which typically results in termination of QUIC server process, leading to Denial of Service. There is so far no evidence that this double free is exploitable for remote code execution, thus it is considered highly improbable. CWE: CWE-415: Double Free Description: In order to validate initial packet, OpenSSL QUIC st

Détails techniques

Vecteur CVSS v3
3.1
Publiée le
2026-08-25
Dernière modification
2026-08-25

Questions fréquentes

Qu’est-ce que CVE-2026-18798 ?

Issue summary: QUIC server may double free QRX (QUIC record layer RX) object when channel creation fails for initial packet. Impact summary: Double free leads to heap corruption, which typically results in termination of QUIC server process, leading to Denial of Service. There is so far no evidence that this double free is exploitable for remote code execution, thus it is considered highly improbable. CWE: CWE-415: Double Free Description: In order to validate initial packet, OpenSSL QUIC st

CVE-2026-18798 est-elle activement exploitée ?

Aucune exploitation active de CVE-2026-18798 n’est confirmée. Le score EPSS est de 1.5 %, soit la probabilité estimée d’exploitation dans les 30 prochains jours.

Quel est le score CVSS de CVE-2026-18798 ?

CVE-2026-18798 a un score de base CVSS v3 de 7.5 (gravité HIGH), avec le vecteur 3.1.

CVE-2026-18798 touche-t-elle votre environnement ?

Utilisez isMalicious pour vérifier si l’une de vos IP ou l’un de vos domaines est associé aux IOC de cette vulnérabilité.

Sans carte bancaire · 500 vérifications gratuites par mois · Clé API gratuite