CVE-2026-42764
OpenSSL OpenSSL, openssl
Issue summary: Receiving a QUIC initial packet with an invalid token may trigger a NULL pointer dereference in the OpenSSL QUIC server with address validation disabled. Impact summary: NULL pointer dereference typically causes abnormal termination of the affected QUIC server process and a Denial of Service. If the address validation is disabled in the OpenSSL QUIC server implementation, an attacker can crash the server by sending an initial packet with an invalid or expired token. By default, the client address validation is enabled in the OpenSSL QUIC server implementation, which makes the...
- CVSS
- 7.5
- EPSS
- 1.17% 64.2% percentile
- CISA KEV
- Not listed
- Published
- 2026.06.10