CVE-2025-4820
Impact
Cloudflare quiche was discovered to be vulnerable to incorrect congestion window growth, which could cause it to send data at a rate faster than the path might actually support.
An unauthenticated remote attacker can exploit the vulnerability by first completing a handshake and initiating a congestion-controlled data transfer towards itself. Then, it could manipulate the victim's congestion control state by sending ACK frames exercising an opportunistic ACK attack; see RFC 9000 Section 21.4. The victim could grow the congestion window beyond typical expectations and allow more bytes in flight than the path might really support.
Leer descripción completaMostrar menos
Patches
quiche 0.24.4 is the earliest version containing the fix for this issue.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
- Puntuación base: 5.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.86%
- Percentil entre todas las CVEs puntuadas: 57
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-770
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-4820",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-4820",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2025-06-18T18:27:27.515226Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "cna@cloudflare.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.3,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "LOW",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 1.4,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "cna@cloudflare.com",
"affectedData": [
{
"vendor": "Cloudflare",
"product": "quiche",
"versions": [
{
"status": "affected",
"version": "<0.24.4"
}
],
"packageName": "cloudflare-quiche",
"defaultStatus": "unaffected"
}
]
}
],
"published": "2025-06-18T16:15:28.403",
"references": [
{
"url": "https://github.com/cloudflare/quiche/security/advisories/GHSA-2v9p-3p3h-w56j",
"tags": [
"Vendor Advisory"
],
"source": "cna@cloudflare.com"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "cna@cloudflare.com",
"description": [
{
"lang": "en",
"value": "CWE-770"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Impact\n\nCloudflare quiche was discovered to be vulnerable to incorrect congestion window growth, which could cause it to send data at a rate faster than the path might actually support.\n\nAn unauthenticated remote attacker can exploit the vulnerability by first completing a handshake and initiating a congestion-controlled data transfer towards itself. Then, it could manipulate the victim's congestion control state by sending ACK frames exercising an opportunistic ACK attack; see RFC 9000 Section 21.4. The victim could grow the congestion window beyond typical expectations and allow more bytes in flight than the path might really support.\n\n\n\nPatches\n\n\nquiche 0.24.4 is the earliest version containing the fix for this issue."
},
{
"lang": "es",
"value": "Se descubrió que Quiche de Cloudflare era vulnerable a un crecimiento incorrecto de la ventana de congestión, lo que podría provocar que enviara datos a una velocidad superior a la que la ruta realmente admite. Un atacante remoto no autenticado puede explotar esta vulnerabilidad completando primero un protocolo de enlace e iniciando una transferencia de datos controlada por congestión hacia sí mismo. Posteriormente, podría manipular el estado de control de congestión de la víctima enviando tramas ACK, lo que implica un ataque ACK oportunista (véase RFC 9000, sección 21.4). La víctima podría aumentar la ventana de congestión más allá de lo esperado y permitir más bytes en tránsito de los que la ruta realmente admite. La versión 0.24.4 de Quiche es la más reciente que corrige este problema."
}
],
"lastModified": "2026-06-17T09:34:05.110",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:cloudflare:quiche:*:*:*:*:*:rust:*:*",
"vulnerable": true,
"matchCriteriaId": "8DAD3DB7-C853-47F1-91E3-BB4B1238498C",
"versionEndExcluding": "0.24.4"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cna@cloudflare.com"
}