quic-go has 5 CVEs on record between 2023 and 2026. 1 was published in the last 90 days. The median CVSS is 5.3 (medium). None have a confirmed exploitation report. Most affected products: github.com/quic-go/quic-go (3), github.com/quic-go/webtransport-go (1), webtransport-go (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 5.3
- Publish → KEV
- —
- Last 90 days
- 1 prev 1
Weakness classes
Products
- github.com/quic-go/quic-go 3
- github.com/quic-go/webtransport-go 1
- webtransport-go 1
Worst active — by depth score
CVE-2025-59530High· 7.5quic-go: Panic occurs when queuing undecryptable packets after handshake completion41CVE-2023-46239High· 7.5quic-go vulnerable to pointer dereference that can lead to panic41CVE-2026-57497Medium· 5.3webtransport-go is an implementation of the WebTransport protocol29CVE-2026-40898Medium· 5.3quic-go: HTTP/3 QPACK Trailer Expansion Memory Exhaustion 29CVE-2026-21438Medium· 5.3webtransport-go: Memory Exhaustion Attack due to Missing Cleanup of Streams Map29
quic-go vulnerabilities
CVEs affecting quic-go, newest first. Open any entry for full detail, references, and exploit status.
5 CVEsRSS
CVE-2026-57497Medium· 5.3webtransport-go is an implementation of the WebTransport protocol
webtransport-go is an implementation of the WebTransport protocol. Prior to 0.11.1, Session.parseNextCapsule() in session.go skips an unknown WebTransport capsule on the HTTP/3 request stream by calling io.ReadAll on the capsule reader, …
CVE-2026-40898Medium· 5.3quic-go: HTTP/3 QPACK Trailer Expansion Memory Exhaustion
quic-go: HTTP/3 QPACK Trailer Expansion Memory Exhaustion
CVE-2026-21438Medium· 5.3webtransport-go: Memory Exhaustion Attack due to Missing Cleanup of Streams Map
webtransport-go: Memory Exhaustion Attack due to Missing Cleanup of Streams Map
CVE-2025-59530High· 7.5quic-go: Panic occurs when queuing undecryptable packets after handshake completion
quic-go: Panic occurs when queuing undecryptable packets after handshake completion
CVE-2023-46239High· 7.5quic-go vulnerable to pointer dereference that can lead to panic
quic-go vulnerable to pointer dereference that can lead to panic