top of page
perceptive_background_267k.jpg

QTI Neon is a minimal, game-agnostic, relay-based UDP multiplayer protocol library. In version 1.0.0, the relay's handleReconnectRequest forwards RECONNECT_REQU…

Published:

27 juli 2026 om 22:00:00

Alert date:

28 juli 2026 om 18:03:14

Source:

nvd.nist.gov

Click to open the original link from this advisory

Network Infrastructure, Zero-Day Vulnerabilities

CVE-2026-54609 affects QTI Neon version 1.0.0, a minimal relay-based UDP multiplayer protocol library. The vulnerability exists in the relay's handleReconnectRequest function, which forwards RECONNECT_REQUEST packets to the host without any rate limiting or bounding. An unauthenticated client can exploit this to drive relay-to-host packet amplification, resulting in a denial of service against the host. The flaw requires no authentication to exploit, lowering the barrier for attack. The issue stems from a lack of input validation and request throttling in the relay logic. As of the time of review, no fixed version of QTI Neon is available. Users of this library are advised to implement external mitigations such as rate limiting at the network level until a patch is released.

Technical details

Mitigation steps:

Affected products:

QTI Neon 1.0.0

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page