Vulnerability record · CVE-2026-40170 · published 16 April 2026
CVE-2026-40170: Tatsuhiro-t ngtcp2 stack-based buffer overflow vulnerability
TTatsuhiro T · Ngtcp2
ngtcp2 is a C implementation of the IETF QUIC protocol. In versions prior to 1.22.1, ngtcp2_qlog_parameters_set_transport_params() serializes peer transport parameters into a fixed 1024-byte stack buffer without bounds checking. When qlog is enabled, a remote peer can send sufficiently large transport parameters during the QUIC handshake to cause writes beyond the buffer boundary, resulting in a stack buffer overflow. This affects deployments that enable the qlog callback and process untrusted peer transport parameters. This issue has been fixed in version 1.22.1. If developers are unable to immediately upgrade, they can disable the qlog on client.
Description
ngtcp2 is a C implementation of the IETF QUIC protocol. In versions prior to 1.22.1, ngtcp2_qlog_parameters_set_transport_params() serializes peer transport parameters into a fixed 1024-byte stack buffer without bounds checking. When qlog is enabled, a remote peer can send sufficiently large transport parameters during the QUIC handshake to cause writes beyond the buffer boundary, resulting in a stack buffer overflow. This affects deployments that enable the qlog callback and process untrusted peer transport parameters. This issue has been fixed in version 1.22.1. If developers are unable to immediately upgrade, they can disable the qlog on client.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/ngtcp2/ngtcp2/commit/708a7640c1f48fb8ffb540c4b8ea5b4c1dfb8ee5 | Patch |
| https://github.com/ngtcp2/ngtcp2/security/advisories/GHSA-f523-465f-8c8f | ExploitMitigationPatchVendor Advisory |
| http://www.openwall.com/lists/oss-security/2026/04/17/12 | ExploitMailing ListMitigationPatchThird Party Advisory |
| https://access.redhat.com/errata/RHSA-2026:22963 | |
| https://access.redhat.com/errata/RHSA-2026:25049 | |
| https://access.redhat.com/errata/RHSA-2026:9113 | |
| https://access.redhat.com/security/cve/CVE-2026-40170 | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2459061 | |
| https://github.com/ngtcp2/ngtcp2/security/advisories/GHSA-f523-465f-8c8f | ExploitMitigationPatchVendor Advisory |
| https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-40170.json |
Track CVE-2026-40170 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2026-40170), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.