CVE-2026-10740 - Excessive memory allocation in s2n-quic
Bulletin ID: 2026-042-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 06/10/2026 11:15 AM PDT Description: s2n-quic is a Rust implementation of the QUIC protocol. We identified CVE-2026-10740, an issue of unbounded memory allocation in the CRYPTO frame reassembler in s2n-quic before 1.82.0. An unauthenticated user can attempt to exhaust server memory on an s2n-quic endpoint by sending crafted CRYPTO frames with high offsets. The buffer used for processing CRYPTO frames does not enforce a maximum size. In the worst case, a single 1200-byte packet can cause approximately 9.4 MB of allocation. By repeatedly sending such packets, the resulting memory pressure could cause denial of service. No valid handshake is required. Impacted versions: < v1.82.0 Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.
CSIRTS triage
- What
- Unbounded memory allocation can lead to denial of service by exhausting server memory.
- Who is affected
- Users of s2n-quic versions before 1.82.0.
- Urgency
- Remediation is important to prevent denial of service attacks.
- Action
- Update s2n-quic to version 1.82.0 or later.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch s2n-quic
Get an email when a new s2n-quic advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://aws.amazon.com/security/security-bulletins/rss/2026-042-aws/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-107400.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 22% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-10740 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
Recent advisories for - Excessive memory
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- mediumGHSA-g6gw-c38x-mqfc: Hono: Unbounded dot-notation nesting in `parseBody()` can cause memory exhaustionghsa · 2026-09-08
- mediumCVE-2026-84685: The react-native-auth0 SDK's web platform implementation does not scope its in-memory token ca…nvd · 2026-09-08
- mediumCVE-2026-81993: Acrobat Reader is affected by a Heap-based Buffer Overflow vulnerability that could lead to di…nvd · 2026-09-08
- mediumCVE-2026-81991: Acrobat Reader is affected by an out-of-bounds read vulnerability that could lead to disclosur…nvd · 2026-09-08
- mediumCVE-2026-81984: Acrobat Reader is affected by a Use After Free vulnerability that could lead to disclosure of …nvd · 2026-09-08
- mediumCVE-2026-81982: Acrobat Reader is affected by an out-of-bounds read vulnerability that could lead to disclosur…nvd · 2026-09-08
More from AWS Security Bulletins
- unknownCVE-2026-84942 - Stored Cross-Site Scripting via Vega Expression Function Bypass in OpenSearch Dashboards2026-09-08
- unknownCVE-2026-85787 - An incomplete list of disallowed inputs in the SQL validation component in Amazon awslabs pos…2026-09-04
- unknownCVE-2026-85654 - Code injection in the CDK generator in Amazon awslabs.dynamodb-mcp-server2026-09-04
- unknownCVE-2026-85786 - Incomplete fix for CVE-2026-75936 memory-amplification denial of service in Amazon ion-java2026-09-04
- unknownCVE-2026-85781 - Unverified access point ownership in Amazon EFS CSI Driver2026-09-04