[Medium] CVE-2026-40898 – quic-go is an implementation of the QUIC protocol in Go. Prior to version 0.59.1...
Medium CVE-2026-40898 quic-go is an implementation of the QUIC protocol in Go. Prior to version 0.59.1, an attacker can cause excessive memory allocation in quic-go's HTTP/3 client and server implementations by sending a QPACK-encoded HEADERS frame that decodes into a large trailer field section...