CVE-2026-18798 | OpenSSL up to 3.5.7/3.6.3/4.0.1 QUIC port_default_packet_handler double free

SecurityVulns

A vulnerability was found in OpenSSL up to 3.5.7/3.6.3/4.0.1. It has been declared as critical. Affected by this issue is the function port_default_packet_handler of the component QUIC. Executing a manipulation can lead to double free.

The identification of this vulnerability is CVE-2026-18798. The attack may be launched remotely. There is no exploit available.

It is recommended to upgrade the affected component.VulDB Recent EntriesRead More