CVE-2024-45396: Dena Quicly

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

Quicly is an IETF QUIC protocol implementation. Quicly up to commtit d720707 is susceptible to a denial-of-service attack. A remote attacker can exploit these bugs to trigger an assertion failure that crashes process using quicly. The vulnerability is addressed with commit 2a95896104901589c495bc41460262e64ffcad5c.

Affected products

  • Dena Quicly: before 2024-10-10 (fixed in 2024-10-10)

Published 2024-10-11. Last modified 2026-06-17.