CVE-2026-12707
Cloudflare quiche
Summary Cloudflare quiche was discovered to be vulnerable to memory resource exhaustion due to unbounded queuing of post-handshake client migration events. Impact quiche supports the connection migration features described in Section 9 of RFC 9000, which allows a single QUIC connection to survive changes in the network path. Although quiche implements the protections described in Section 9.3 of RFC 9000 to limit server state commitment, it was discovered that the collection of PathEvents, intended to be consumed by applications via the path_event_next() function, was not bounded. Once the Q...
- CVSS
- 7.5
- EPSS
- 0.29% 20.9% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.15