CVE-2026-94450 - Potential denial of service when configured to send Retry packets in s2n-quic
Bulletin ID: 2026-116-AWS
Scope: AWS
Content Type: Important (requires attention)
Publication Date: 09/22/2026 13:00 PM PDT
Description:
s2n-quic is a Rust implementation of the QUIC protocol. We identified CVE-2026-94450, an issue with improper validation of the Destination Connection ID length when a server is configured to send Retry packets. s2n-quic 1.88.0 and earlier allow an unauthenticated user to shut down a server endpoint via a single crafted UDP datagram. No AWS services are affected by this issue, and customers of AWS services do not need to take action. Only server endpoints specifically configured to issue Retry packets are affected.
Impacted versions: <= v1.88.0
Resolution:
This issue has been addressed in s2n-quic version 1.89.0. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes.
Workarounds:
There is no workaround that mitigates this issue. Upgrading to the patched version is the recommended remediation.
References:
Please email aws-security@amazon.com with any security questions or concerns.