


Perceptive Security
SOC/SIEM Consultancy

QTI Neon is a minimal, game-agnostic, relay-based UDP multiplayer protocol library. In version 1.0.0, the relay's handleReconnectRequest forwards RECONNECT_REQU…
Published:
28 juli 2026 om 00:00:00
Alert date:
28 juli 2026 om 20:03:14
Source:
nvd.nist.gov
Network Infrastructure, Zero-Day Vulnerabilities
CVE-2026-54609 affects QTI Neon version 1.0.0, a minimal relay-based UDP multiplayer protocol library. The vulnerability exists in the relay's handleReconnectRequest function, which forwards RECONNECT_REQUEST packets to the host without any rate limiting or bounding. An unauthenticated client can exploit this to drive relay-to-host packet amplification, resulting in a denial of service against the host. The flaw requires no authentication to exploit, lowering the barrier for attack. The issue stems from a lack of input validation and request throttling in the relay logic. As of the time of review, no fixed version of QTI Neon is available. Users of this library are advised to implement external mitigations such as rate limiting at the network level until a patch is released.
Technical details
Mitigation steps:
Affected products:
QTI Neon 1.0.0
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-54609
https://github.com/Quiet-Terminal-Interactive/QTINeon/security/advisories/GHSA-85rg-p3fr-xc2f
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
