{"id":"GHSA-hqqc-jr88-p6x2","summary":"Netty QUIC hash collision DoS attack","details":"An issue was discovered in the codec. A hash collision vulnerability (in the hash map used to manage connections) allows remote attackers to cause a considerable CPU load on the server (a Hash DoS attack) by initiating connections with colliding Source Connection IDs (SCIDs).\n\nSee https://github.com/ncc-pbottine/QUIC-Hash-Dos-Advisory","aliases":["CVE-2025-29908"],"modified":"2025-03-31T22:10:24.710620Z","published":"2025-03-31T21:47:20Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2025-03-31T21:47:20Z","nvd_published_at":"2025-03-31T19:15:40Z","cwe_ids":["CWE-407"],"severity":"MODERATE"},"references":[{"type":"WEB","url":"https://github.com/netty/netty-incubator-codec-quic/security/advisories/GHSA-hqqc-jr88-p6x2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-29908"},{"type":"WEB","url":"https://github.com/netty/netty-incubator-codec-quic/commit/e059bd9b78723f8b035e0c547e42ce263f03461c"},{"type":"WEB","url":"https://github.com/ncc-pbottine/QUIC-Hash-Dos-Advisory"},{"type":"PACKAGE","url":"https://github.com/netty/netty-incubator-codec-quic"}],"affected":[{"package":{"name":"io.netty.incubator:netty-incubator-codec-quic","ecosystem":"Maven","purl":"pkg:maven/io.netty.incubator/netty-incubator-codec-quic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.0.71.Final"}]}],"versions":["0.0.1.Final","0.0.10.Final","0.0.11.Final","0.0.12.Final","0.0.13.Final","0.0.14.Final","0.0.15.Final","0.0.16.Final","0.0.17.Final","0.0.18.Final","0.0.19.Final","0.0.2.Final","0.0.20.Final","0.0.3.Final","0.0.4.Final","0.0.5.Final","0.0.6.Final","0.0.7.Final","0.0.8.Final","0.0.9.Final"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/03/GHSA-hqqc-jr88-p6x2/GHSA-hqqc-jr88-p6x2.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"}]}