Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-85rg-p3fr-xc2f | QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding |
Tue, 28 Jul 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 28 Jul 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | QTI Neon is a minimal, game-agnostic, relay-based UDP multiplayer protocol library. In version 1.0.0, the relay's handleReconnectRequest forwards RECONNECT_REQUEST packets to the host without bounding them, so an unauthenticated client can drive relay-to-host amplification and cause a denial of service on the host. No fixed version is available as of this review. | |
| Title | QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding | |
| Weaknesses | CWE-400 CWE-406 CWE-770 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-07-28T17:07:15.080Z
Reserved: 2026-06-15T19:45:23.540Z
Link: CVE-2026-54609
Updated: 2026-07-28T17:06:56.770Z
No data.
No data.
OpenCVE Enrichment
No data.
Github GHSA