CVE-2026-54609

QTI Neon is a minimal, game-agnostic, relay-based UDP multiplayer protocol library. In version 1.0.0, the relay's handleReconnectRequest forwards RECONNECT_REQUEST packets to the host without bounding them, so an unauthenticated client can drive relay-to-host amplification and cause a denial of service on the host. No fixed version is available as of this review.
Configurations

No configuration.

History

No history.

Information

Published : 2026-07-28 17:16

Updated : 2026-07-30 19:59


NVD link : CVE-2026-54609

Mitre link : CVE-2026-54609

CVE.ORG link : CVE-2026-54609


JSON object : View

Products Affected

No product.

CWE
CWE-400

Uncontrolled Resource Consumption

CWE-406

Insufficient Control of Network Message Volume (Network Amplification)

CWE-770

Allocation of Resources Without Limits or Throttling