CVE Feed

    Dashboard / CVE / CVE-2026-40170

    CVE-2026-40170

    ngtcp2 is a C implementation of the IETF QUIC protocol. In versions prior to 1.22.1, ngtcp2_qlog_parameters_set_transport_params() serializes peer transport parameters into a fixed 1024-byte stack buffer without bounds checking. When qlog is enabled, a remote peer can send sufficiently large transport parameters during the QUIC handshake to cause writes beyond the buffer boundary, resulting in a stack buffer overflow. This affects deployments that enable the qlog callback and process untrusted peer transport parameters. This issue has been fixed in version 1.22.1. If developers are unable to immediately upgrade, they can disable the qlog on client.

    Published:Apr 16, 2026
    Last Modified:May 22, 2026
    EPS:Apr 16, 2026
    EPSS Score:0.00017
    CVSS Score:7.5

    Affected Products

    Vendor
    Ngtcp2
    Product
    Ngtcp2
    Vendor
    Tatsuhiro-t
    Product
    Ngtcp2

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High