THREAT OPS › Threat News › [NVD] CVE-2026-63075 (HIGH 7.5) — Issue summary: When OpenSSL processes QUIC traffic from a peer that repeatedly
sends ack-eliciting packets while not acknowledging ACK-only responses, the
QUIC stack can retain ACK-only packet metadata for the lifetime of the
connection.
Impact summary: A remote peer that can co
[NVD] CVE-2026-63075 (HIGH 7.5) — Issue summary: When OpenSSL processes QUIC traffic from a peer that repeatedly sends ack-eliciting packets while not acknowledging ACK-only responses, the QUIC stack can retain ACK-only packet metadata for the lifetime of the connection. Impact summary: A remote peer that can co
CVE-2026-63075 CVSS: 7.5 HIGH Published: 2026-08-25T13:19:26.413
Issue summary: When OpenSSL processes QUIC traffic from a peer that repeatedly sends ack-eliciting packets while not acknowledging ACK-only responses, the QUIC stack can retain ACK-only packet metadata for the lifetime of the connection.
Impact summary: A remote peer that can complete a QUIC handshake can cause connection-scoped me
Indicators of compromise
- CVE-2026-63075cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-63075