---
id: CVE-2026-44894
aliases:
  - GHSA-cmm3-54f8-px4j
title: Netty's Default QUIC token handler accepts any client-supplied token
summary: Netty's Default QUIC token handler accepts any client-supplied token
severity: high
cvss: 7.5
cwe:
  - CWE-940
vendor: netty
product: 'io.netty:netty-codec-classes-quic'
ecosystem: maven
affected:
  - 'io.netty:netty-codec-classes-quic >= 4.2.0.Final, <= 4.2.14.Final'
patched:
  - 'io.netty:netty-codec-classes-quic 4.2.15.Final'
published: '2026-06-08'
updated: '2026-06-12'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-cmm3-54f8-px4j'
references:
  - url: 'https://github.com/netty/netty/security/advisories/GHSA-cmm3-54f8-px4j'
  - url: 'https://github.com/netty/netty/releases/tag/netty-4.2.15.Final'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-44894'
  - url: 'https://github.com/advisories/GHSA-cmm3-54f8-px4j'
tags:
  - ghsa
  - maven
epss: 0.00191
epssPercentile: 0.07793
ingestedAt: '2026-07-07T15:41:59.860Z'
---

## Overview

NoQuicTokenHandler is the tokenHandler used when the application does not set one. Its writeToken() returns false (server will not send Retry — acceptable), but validateToken() unconditionally `return 0`. In QuicheQuicServerCodec.handlePacket(), a non-negative return from validateToken() is interpreted as 'token is valid, ODCID starts at offset 0', causing the server to call quiche_accept as if the client's address had been validated by a Retry round-trip. Per RFC 9000 §8.1, a validated address lifts the 3× anti-amplification send limit. Thus any attacker who includes ANY non-empty token bytes in an Initial packet — with a spoofed victim source IP — causes the Netty server to treat the victim as validated and reflect full-size handshake flights (certificates, etc.) toward it without the 3× cap. The correct 'no token handler' semantics would be to return -1 (invalid) so the normal un-validated path and amplification limit apply.

## Affected packages

- `io.netty:netty-codec-classes-quic >= 4.2.0.Final, <= 4.2.14.Final`

## Remediation

Upgrade to a patched release:

- `io.netty:netty-codec-classes-quic 4.2.15.Final`
