CVE-2026-40170Disclosure(tatsuhiro-t / ngtcp2)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch tatsuhiro-t ngtcp2 systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

ngtcp2 is a C implementation of the IETF QUIC protocol. In versions prior to 1.22.1, ngtcp2_qlog_parameters_set_transport_params() serializes peer transport parameters into a fixed 1024-byte stack buffer without bounds checking. When qlog is enabled, a remote peer can send sufficiently large transport parameters during the QUIC handshake to cause writes beyond the buffer boundary, resulting in a stack buffer overflow. This affects deployments that enable the qlog callback and process untrusted peer transport parameters. This issue has been fixed in version 1.22.1. If developers are unable to immediately upgrade, they can disable the qlog on client.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-121CWE-120

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ngtcp2

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-04-17); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Products
ngtcp2

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-17: 2Mentions · 2026-04-19: 1Patch / Workaround · 2026-04-17: 1Technical Details · 2026-04-17: 1Technical Details · 2026-04-19: 104-1704-19
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-172
Disclosure1Patch1
2026-04-191
Disclosure1
Full discourse3 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2026-40170: ngtcp2: ngtcp2_qlog_parameters_set_transport_params() stack buffer overflow https://www.openwall.com/lists/oss-security/2026/04/17/12 serializes transport parameters into a fixed stack buffer (uint8_t buf[1024]) without complete bounds checks

    Post summary

    The post discloses a stack buffer overflow in ngtcp2, providing technical details but no PoC, exploit, or patch information.

    00020386
    4.7K followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-ngtcp2 Module Update 1.22.1-1 https://kusanagi.tokyo/en/releases/24356/ KUSANAGI 9 modules have been updated. The updated modules are as follows: ngtcp2 1.22.1-1 This update includes support for vulnerability(CVE-2026-40170). The module update can be applied with the following...

    Post summary

    The text announces a module update for kusanagi-ngtcp2 that contains a fix for CVE-2026-40170, providing a patch without listing any exploit details or active exploitation.

    0101078
    200 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-40170 ngtcp2 is a C implementation of the IETF QUIC protocol. In versions prior to 1.22.1, ngtcp2_qlog_parameters_set_transport_params() serializes peer transport parameter… https://www.cve.org/CVERecord?id=CVE-2026-40170

    Post summary

    The notice reports a serialization bug in ngtcp2 prior to 1.22.1, providing technical details but no PoC, exploit, or patch information.

    0000087
    57.2K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apptatsuhiro-tngtcp2---

Explore more