CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

CVE-2026-14456: OpenSSL QUIC Server Flaw Allows Unbounded Connection Queuing

August 20, 2026

OpenSSL disclosed a low-severity flaw in QUIC servers that queue incoming channels for unknown destination connection IDs without enforcing a limit, potentially leading to resource exhaustion. The fix introduces a default limit of 256 pending connections.