{"id":"CVE-2026-44894","aliases":["GHSA-cmm3-54f8-px4j"],"title":"Netty's Default QUIC token handler accepts any client-supplied token","summary":"Netty's Default QUIC token handler accepts any client-supplied token","severity":"high","cvss":7.5,"cwe":["CWE-940"],"vendor":"netty","product":"io.netty:netty-codec-classes-quic","ecosystem":"maven","affected":["io.netty:netty-codec-classes-quic >= 4.2.0.Final, <= 4.2.14.Final"],"patched":["io.netty:netty-codec-classes-quic 4.2.15.Final"],"published":"2026-06-08","updated":"2026-06-12","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-cmm3-54f8-px4j","references":[{"url":"https://github.com/netty/netty/security/advisories/GHSA-cmm3-54f8-px4j"},{"url":"https://github.com/netty/netty/releases/tag/netty-4.2.15.Final"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44894"},{"url":"https://github.com/advisories/GHSA-cmm3-54f8-px4j"}],"tags":["ghsa","maven"],"epss":0.00143,"epssPercentile":0.03944,"ingestedAt":"2026-07-07T15:41:59.860Z","slug":"CVE-2026-44894","body":"## Overview\n\nNoQuicTokenHandler is the tokenHandler used when the application does not set one. Its writeToken() returns false (server will not send Retry — acceptable), but validateToken() unconditionally `return 0`. In QuicheQuicServerCodec.handlePacket(), a non-negative return from validateToken() is interpreted as 'token is valid, ODCID starts at offset 0', causing the server to call quiche_accept as if the client's address had been validated by a Retry round-trip. Per RFC 9000 §8.1, a validated address lifts the 3× anti-amplification send limit. Thus any attacker who includes ANY non-empty token bytes in an Initial packet — with a spoofed victim source IP — causes the Netty server to treat the victim as validated and reflect full-size handshake flights (certificates, etc.) toward it without the 3× cap. The correct 'no token handler' semantics would be to return -1 (invalid) so the normal un-validated path and amplification limit apply.\n\n## Affected packages\n\n- `io.netty:netty-codec-classes-quic >= 4.2.0.Final, <= 4.2.14.Final`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `io.netty:netty-codec-classes-quic 4.2.15.Final`","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}