github.com/quic-go/quic-go vulnerabilities
CVEs whose affected-version data names the github.com/quic-go/quic-go package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
3 CVEsRSS
CVE-2026-40898Medium· 5.3quic-go: HTTP/3 QPACK Trailer Expansion Memory Exhaustion
quic-go: HTTP/3 QPACK Trailer Expansion Memory Exhaustion
▾ Sunlitquic-go · github.com/quic-go/quic-goEPSS 0.40%via OSV
CVE-2025-59530High· 7.5quic-go: Panic occurs when queuing undecryptable packets after handshake completion
quic-go: Panic occurs when queuing undecryptable packets after handshake completion
▾ Twilightquic-go · github.com/quic-go/quic-goEPSS 0.46%via OSV
CVE-2023-46239High· 7.5quic-go vulnerable to pointer dereference that can lead to panic
quic-go vulnerable to pointer dereference that can lead to panic
▾ Twilightquic-go · github.com/quic-go/quic-goEPSS 0.77%via OSV