CVE-2026-50009 is an information disclosure vulnerability in Netty QUIC affecting versions prior to 4.2.15.Final. When Netty QUIC uses its default HMAC-based connection ID and stateless reset token generators, the design allows the stateless reset token associated with the server's current source connection ID to be derived from connection ID bytes that become visible in QUIC packet headers after source connection ID rotation. The vulnerable implementation uses the same HMAC-based derivation context for both connection IDs and stateless reset tokens, creating a relationship between header-visible connection identifiers and the token material. An attacker positioned on the network path can observe the rotated connection ID in cleartext QUIC headers, derive the corresponding 16-byte stateless reset token, and then forge a QUIC Stateless Reset packet that the client accepts as valid. Netty 4.2.15.Final changes reset-token derivation to use separate keying material or domain separation, preventing derivation from observed connection IDs.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A vulnerability in Netty QUIC stateless reset token generation where shared key/derivation logic allows an on-path attacker to derive the active Stateless Reset Token after Connection ID rotation and spoof a QUIC Stateless Reset, causing connection termination.
A Netty QUIC flaw where shared static-key derivation enables an on-path observer to derive stateless reset tokens from visible connection IDs and spoof resets, causing denial of service.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.