THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-63075 (HIGH 7.5) — Issue summary: When OpenSSL processes QUIC traffic from a peer that repeatedly sends ack-eliciting packets while not acknowledging ACK-only responses, the QUIC stack can retain ACK-only packet metadata for the lifetime of the connection. Impact summary: A remote peer that can co

[NVD] CVE-2026-63075 (HIGH 7.5) — Issue summary: When OpenSSL processes QUIC traffic from a peer that repeatedly sends ack-eliciting packets while not acknowledging ACK-only responses, the QUIC stack can retain ACK-only packet metadata for the lifetime of the connection. Impact summary: A remote peer that can co

mednvdPublished 2026-08-25

CVE-2026-63075 CVSS: 7.5 HIGH Published: 2026-08-25T13:19:26.413

Issue summary: When OpenSSL processes QUIC traffic from a peer that repeatedly sends ack-eliciting packets while not acknowledging ACK-only responses, the QUIC stack can retain ACK-only packet metadata for the lifetime of the connection.

Impact summary: A remote peer that can complete a QUIC handshake can cause connection-scoped me

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-63075