CVE-2026-54609: Uncontrolled Resource Consumption and Network Amplification in QTINeon
Vulnerability ID: CVE-2026-54609
CVSS Score: 8.6
Published: 2026-07-28
Quiet-Terminal-Interactive's QTINeon version 1.0.0 is vulnerable to uncontrolled resource consumption and relay-to-host network amplification. The reconnect request handler lacks table size constraints, rate limiting, and request deduplication, allowing unauthenticated attackers to crash the relay server and overwhelm target hosts.
TL;DR
An unauthenticated remote attacker can exploit the QTINeon reconnect handler to exhaust relay server memory and launch network amplification attacks against target game hosts.
Technical Details
- CWE ID: CWE-400
- Attack Vector: Network (AV:N)
- CVSS Score: 8.6
- Scope: Changed (S:C)
- Impact: Availability (A:H)
- Exploit Status: none
- KEV Status: Not Listed
Affected Systems
- QTINeon UDP Relay Server
-
QTINeon: == 1.0.0 (Fixed in:
None)
Mitigation Strategies
- Enforce hard limits on the size of internal state mapping tables.
- Implement request deduplication based on unique client identifiers.
- Apply rate limiting to all packet-forwarding functions in the relay.
- Enforce automated timed pruning of stale connection mappings.
Remediation Steps:
- Open the QTINeon server source code files containing the reconnect logic.
- Locate the handleReconnectRequest function processing RECONNECT_REQUEST packets.
- Declare a maximum capacity limit constant (e.g., MaxPendingReconnects = 1024).
- Add a validation check at the beginning of the function to reject incoming packets if the size threshold is exceeded.
- Check if the unique client ID is already present in the map; discard duplicate requests.
- Integrate a background timer or polling job that sweeps and purges expired entries from the dictionary.
References
Read the full report for CVE-2026-54609 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)