CVE-2026-40170: ngtcp2 has a qlog transport parameter serialization stack buffer overflow
Published Apr 16, 2026
·Updated
Last updated 13 May 2026
Affected Software
3 affected componentsFixes available
ngtcp2 ngtcp2<1.22.1
nghttp2 Ngtcp2<1.22.1
debian/ngtcp2
0.12.1+dfsg-1+deb12u11.11.0-1+deb13u11.22.1-1
Remediation
Patch Available
Event History
Apr 16, 2026
CVE Published
via MITRE·09:34 PM
Data Sourced
via MITRE·09:34 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
May 25, 2026
Data Sourced
via Ubuntu·03:05 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·03:06 PM
DescriptionAffected Software
Data Sourced
via Launchpad·03:06 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2026-40170?
CVE-2026-40170 is classified as a high-severity vulnerability due to its potential to cause a stack buffer overflow.
2
How do I fix CVE-2026-40170?
To fix CVE-2026-40170, update ngtcp2 to version 1.22.1 or later.
3
Which versions of ngtcp2 are affected by CVE-2026-40170?
CVE-2026-40170 affects ngtcp2 versions prior to 1.22.1.
4
What kind of vulnerability is CVE-2026-40170?
CVE-2026-40170 is a stack buffer overflow vulnerability resulting from improper handling of transport parameters.
5
What impact does CVE-2026-40170 have on systems?
CVE-2026-40170 could lead to arbitrary code execution or denial of service due to the buffer overflow.