Defending QUIC from acknowledgement-based DDoS attacks
blog.cloudflare.com·15h·
Discuss: Hacker News
Flag this post

2025-10-29

9 min read

On April 10th, 2025 12:10 UTC, a security researcher notified Cloudflare of two vulnerabilities (CVE-2025-4820 and CVE-2025-4821) related to QUIC packet acknowledgement (ACK) handling, through our Public Bug Bounty program. These were DDoS vulnerabilities in the quiche library, and Cloudflare services that use it. quiche is Cloudflare’s open-source implementation of QUIC protocol, which is the transport protocol behind [HTTP/3](https://blog.cloudflare.com/h…

Similar Posts

Loading similar posts...