CVE Explorer
CVE-2026-42764
Issue summary: Receiving a QUIC initial packet with an invalid token may
trigger a NULL pointer dereference in the OpenSSL QUIC server with
address validation disabled.
Impact summary: NULL pointer dereference typically causes abnormal termination
of the affected QUIC server process and a Denial of Service.
If the address validation is disabled in the OpenSSL QUIC server
implementation, an attacker can crash the server by sending an initial
packet with an invalid or expired token.
By default,
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"OpenSSL","vendor":"OpenSSL","versions":[{"lessThan":"4.0.1","status":"affected","version":"4.0.0","versionType":"semver"},{"lessThan":"3.6.3","status":"affected","version":"3.6.0","versionType":"semver"},{"lessThan":"3.5.7","status":"affected","version":"3.5.0","versionType":"semver"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:606ad376a741d0887ff9e49629327dd11c00ebfe2eb0108c90f7f3880af9e413 · sha256:761405db808ce040… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:606ad376a741d0887ff9e49629327dd11c00ebfe2eb0108c90f7f3880af9e413 · sha256:761405db808ce040… · /containers/adp/0/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-476","description":"CWE-476 NULL Pointer Dereference","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:606ad376a741d0887ff9e49629327dd11c00ebfe2eb0108c90f7f3880af9e413 · sha256:761405db808ce040… · /containers/cna/problemTypes/0/descriptions/0
Source references
4 source assertions{"name":"3.5.7 git commit","tags":["patch"],"url":"https://github.com/openssl/openssl/commit/5e3ed291b8af0b03d5d3b9e56a1da69a187e9729"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:606ad376a741d0887ff9e49629327dd11c00ebfe2eb0108c90f7f3880af9e413 · sha256:761405db808ce040… · /containers/cna/references/3
{"name":"3.6.3 git commit","tags":["patch"],"url":"https://github.com/openssl/openssl/commit/a45a0aba8095682c88ff4fc4a784892b8c6f0677"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:606ad376a741d0887ff9e49629327dd11c00ebfe2eb0108c90f7f3880af9e413 · sha256:761405db808ce040… · /containers/cna/references/2
{"name":"4.0.1 git commit","tags":["patch"],"url":"https://github.com/openssl/openssl/commit/bf29a458c1a231eca87e384c62b9c2553fa57a91"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:606ad376a741d0887ff9e49629327dd11c00ebfe2eb0108c90f7f3880af9e413 · sha256:761405db808ce040… · /containers/cna/references/1
{"name":"OpenSSL Advisory","tags":["vendor-advisory"],"url":"https://openssl-library.org/news/secadv/20260609.txt"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:606ad376a741d0887ff9e49629327dd11c00ebfe2eb0108c90f7f3880af9e413 · sha256:761405db808ce040… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.