Skip to main content
Version: v1.4.x

CVE-2026-42772

CVE Details​

Visit the official vulnerability details page for CVE-2026-42772 to learn more.

Initial Publication​

09/29/2026

Last Update​

09/29/2026

Third Party Dependency​

openssl-libs

NIST CVE Summary​

Issue summary: The QUIC stream reassembly algorithm performance deteriorates progressively as packets are arriving out of order. The worst case has a quadratic complexity proportional to the number of stream frames kept in the buffer for the received stream data.

Impact summary: A remote QUIC peer that completes the handshake can create a connection-scoped CPU pressure and potentially a Denial of Service using compliant STREAM frames inside the advertised receive window, with low attacker bandwidth.

CWE: CWE-407: Inefficient Algorithmic Complexity

Description: OpenSSL manages received QUIC stream fragments using a doubly-linked list. While it optimizes for append operations (at the end of the list), it falls back to a head-to-tail linear search for any fragment that does not immediately follow the current `tail`.

By manipulating the sequence of offsets, an attacker can force the server to perform O(n^2) operations, consuming excessive CPU time for the QUIC process.

FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary.

CVE Severity​

0

Our Official Summary​

Investigation is ongoing to determine how this vulnerability affects our products.

Status​

Awaiting Analysis

Affected Products & Versions​

VersionPaletteAIPaletteAI VerteX
1.4.0⚠️ Impacted⚠️ Impacted
1.3.2⚠️ Impacted⚠️ Impacted
1.2.2⚠️ Impacted⚠️ Impacted

Revision History​

No revisions available.