The vulnerability exists due to inefficient processing complexity inside the QUIC and HTTP/3 header validation engine. Crafting specialized packet sequences with massive arrays of pseudo-headers causes the regex or tokenization loops to experience exponential compute slowdowns.