quinn-proto
Async-friendly QUIC implementation in Rust
Activity
- Latest release
- 1h ago
- Total releases
- 50
- Cadence
- ~28 days
- Last 12 months
- 5
Reach
- Downloads
- 272.0M
- Stars
- 5.3k
Details
- License
- MIT OR Apache-2.0
- First release
- Oct 02, 2018
| Version | Released | |
|---|---|---|
0.11.18
patch
|
0.11.18
patch
Dependencies (25)
+ 17 more
Changelog
Compare changes
|
|
0.11.17
patch
|
0.11.17
patch
Dependencies (25)
+ 17 more
Changelog
Compare changes
|
|
0.11.16
unknown
|
0.11.16
unknown
Dependencies (25)
+ 17 more
Changelog
Compare changes
|
|
0.11.15
unknown
|
0.11.15
unknown
Dependencies (25)
+ 17 more
Changelog
Compare changes
|
|
0.11.14
unknown
1 CVE
CVE-2026-25800
GHSA-4w2j-m93h-cj5j
RUSTSEC-2026-0185
Jul 24, 2026
Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassembly
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryThe Fixed in
0.11.15
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.11.14
unknown
Dependencies (25)
+ 17 more
Changelog
Compare changes
|
|
0.11.13
unknown
2 CVEs
CVE-2026-25800
GHSA-4w2j-m93h-cj5j
RUSTSEC-2026-0185
Jul 24, 2026
Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassembly
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryThe Fixed in
0.11.15
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-31812
GHSA-6xvm-j4wr-6v98
RUSTSEC-2026-0037
Mar 11, 2026
Quinn affected by unauthenticated remote DoS via panic in QUIC transport parameter parsing
High
Network
Low
None
None
SummaryA remote, unauthenticated attacker can trigger a denial of service in applications using vulnerable DetailsThe issue is panic-on-untrusted-input in QUIC transport parameter parsing.
In Observed output:
PoCReproduces against the upstream Quinn server example.
Observed output
ImpactVulnerability type: Remote Denial of Service (panic/crash)
Attack requirements: Network reachability to UDP QUIC listener
Authentication/privileges: None
Who is impacted: Any server/application using affected This vulnerability was originally submitted by @revofusion to the Ethereum Foundation bug bounty program Fixed in
0.11.14
References Updated Sep 10, 2026 · Source: OSV.dev |
0.11.13
unknown
Dependencies (25)
+ 17 more
Changelog
Compare changes
|
|
0.11.12
unknown
2 CVEs
CVE-2026-25800
GHSA-4w2j-m93h-cj5j
RUSTSEC-2026-0185
Jul 24, 2026
Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassembly
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryThe Fixed in
0.11.15
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-31812
GHSA-6xvm-j4wr-6v98
RUSTSEC-2026-0037
Mar 11, 2026
Quinn affected by unauthenticated remote DoS via panic in QUIC transport parameter parsing
High
Network
Low
None
None
SummaryA remote, unauthenticated attacker can trigger a denial of service in applications using vulnerable DetailsThe issue is panic-on-untrusted-input in QUIC transport parameter parsing.
In Observed output:
PoCReproduces against the upstream Quinn server example.
Observed output
ImpactVulnerability type: Remote Denial of Service (panic/crash)
Attack requirements: Network reachability to UDP QUIC listener
Authentication/privileges: None
Who is impacted: Any server/application using affected This vulnerability was originally submitted by @revofusion to the Ethereum Foundation bug bounty program Fixed in
0.11.14
References Updated Sep 10, 2026 · Source: OSV.dev |
0.11.12
unknown
Dependencies (24)
+ 16 more
Changelog
Compare changes
|
|
0.11.11
unknown
2 CVEs
CVE-2026-25800
GHSA-4w2j-m93h-cj5j
RUSTSEC-2026-0185
Jul 24, 2026
Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassembly
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryThe Fixed in
0.11.15
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-31812
GHSA-6xvm-j4wr-6v98
RUSTSEC-2026-0037
Mar 11, 2026
Quinn affected by unauthenticated remote DoS via panic in QUIC transport parameter parsing
High
Network
Low
None
None
SummaryA remote, unauthenticated attacker can trigger a denial of service in applications using vulnerable DetailsThe issue is panic-on-untrusted-input in QUIC transport parameter parsing.
In Observed output:
PoCReproduces against the upstream Quinn server example.
Observed output
ImpactVulnerability type: Remote Denial of Service (panic/crash)
Attack requirements: Network reachability to UDP QUIC listener
Authentication/privileges: None
Who is impacted: Any server/application using affected This vulnerability was originally submitted by @revofusion to the Ethereum Foundation bug bounty program Fixed in
0.11.14
References Updated Sep 10, 2026 · Source: OSV.dev |
0.11.11
unknown
Dependencies (21)
+ 13 more
Changelog
Compare changes
|
|
0.11.10
unknown
2 CVEs
CVE-2026-25800
GHSA-4w2j-m93h-cj5j
RUSTSEC-2026-0185
Jul 24, 2026
Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassembly
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryThe Fixed in
0.11.15
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-31812
GHSA-6xvm-j4wr-6v98
RUSTSEC-2026-0037
Mar 11, 2026
Quinn affected by unauthenticated remote DoS via panic in QUIC transport parameter parsing
High
Network
Low
None
None
SummaryA remote, unauthenticated attacker can trigger a denial of service in applications using vulnerable DetailsThe issue is panic-on-untrusted-input in QUIC transport parameter parsing.
In Observed output:
PoCReproduces against the upstream Quinn server example.
Observed output
ImpactVulnerability type: Remote Denial of Service (panic/crash)
Attack requirements: Network reachability to UDP QUIC listener
Authentication/privileges: None
Who is impacted: Any server/application using affected This vulnerability was originally submitted by @revofusion to the Ethereum Foundation bug bounty program Fixed in
0.11.14
References Updated Sep 10, 2026 · Source: OSV.dev |
0.11.10
unknown
Dependencies (21)
+ 13 more
Changelog
Compare changes
|
|
0.11.9
unknown
2 CVEs
CVE-2026-25800
GHSA-4w2j-m93h-cj5j
RUSTSEC-2026-0185
Jul 24, 2026
Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassembly
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryThe Fixed in
0.11.15
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-31812
GHSA-6xvm-j4wr-6v98
RUSTSEC-2026-0037
Mar 11, 2026
Quinn affected by unauthenticated remote DoS via panic in QUIC transport parameter parsing
High
Network
Low
None
None
SummaryA remote, unauthenticated attacker can trigger a denial of service in applications using vulnerable DetailsThe issue is panic-on-untrusted-input in QUIC transport parameter parsing.
In Observed output:
PoCReproduces against the upstream Quinn server example.
Observed output
ImpactVulnerability type: Remote Denial of Service (panic/crash)
Attack requirements: Network reachability to UDP QUIC listener
Authentication/privileges: None
Who is impacted: Any server/application using affected This vulnerability was originally submitted by @revofusion to the Ethereum Foundation bug bounty program Fixed in
0.11.14
References Updated Sep 10, 2026 · Source: OSV.dev |
0.11.9
unknown
Dependencies (21)
+ 13 more
Changelog
Compare changes
|
|
0.11.8
unknown
2 CVEs
CVE-2026-25800
GHSA-4w2j-m93h-cj5j
RUSTSEC-2026-0185
Jul 24, 2026
Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassembly
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryThe Fixed in
0.11.15
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-31812
GHSA-6xvm-j4wr-6v98
RUSTSEC-2026-0037
Mar 11, 2026
Quinn affected by unauthenticated remote DoS via panic in QUIC transport parameter parsing
High
Network
Low
None
None
SummaryA remote, unauthenticated attacker can trigger a denial of service in applications using vulnerable DetailsThe issue is panic-on-untrusted-input in QUIC transport parameter parsing.
In Observed output:
PoCReproduces against the upstream Quinn server example.
Observed output
ImpactVulnerability type: Remote Denial of Service (panic/crash)
Attack requirements: Network reachability to UDP QUIC listener
Authentication/privileges: None
Who is impacted: Any server/application using affected This vulnerability was originally submitted by @revofusion to the Ethereum Foundation bug bounty program Fixed in
0.11.14
References Updated Sep 10, 2026 · Source: OSV.dev |
0.11.8
unknown
Dependencies (16)
+ 8 more
Changelog
Compare changes
|
|
0.11.7
unknown
2 CVEs
CVE-2026-25800
GHSA-4w2j-m93h-cj5j
RUSTSEC-2026-0185
Jul 24, 2026
Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassembly
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryThe Fixed in
0.11.15
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-31812
GHSA-6xvm-j4wr-6v98
RUSTSEC-2026-0037
Mar 11, 2026
Quinn affected by unauthenticated remote DoS via panic in QUIC transport parameter parsing
High
Network
Low
None
None
SummaryA remote, unauthenticated attacker can trigger a denial of service in applications using vulnerable DetailsThe issue is panic-on-untrusted-input in QUIC transport parameter parsing.
In Observed output:
PoCReproduces against the upstream Quinn server example.
Observed output
ImpactVulnerability type: Remote Denial of Service (panic/crash)
Attack requirements: Network reachability to UDP QUIC listener
Authentication/privileges: None
Who is impacted: Any server/application using affected This vulnerability was originally submitted by @revofusion to the Ethereum Foundation bug bounty program Fixed in
0.11.14
References Updated Sep 10, 2026 · Source: OSV.dev |
0.11.7
unknown
Dependencies (16)
+ 8 more
Changelog
Compare changes
|
|
0.11.6
unknown
3 CVEs
CVE-2026-25800
GHSA-4w2j-m93h-cj5j
RUSTSEC-2026-0185
Jul 24, 2026
Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassembly
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryThe Fixed in
0.11.15
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-31812
GHSA-6xvm-j4wr-6v98
RUSTSEC-2026-0037
Mar 11, 2026
Quinn affected by unauthenticated remote DoS via panic in QUIC transport parameter parsing
High
Network
Low
None
None
SummaryA remote, unauthenticated attacker can trigger a denial of service in applications using vulnerable DetailsThe issue is panic-on-untrusted-input in QUIC transport parameter parsing.
In Observed output:
PoCReproduces against the upstream Quinn server example.
Observed output
ImpactVulnerability type: Remote Denial of Service (panic/crash)
Attack requirements: Network reachability to UDP QUIC listener
Authentication/privileges: None
Who is impacted: Any server/application using affected This vulnerability was originally submitted by @revofusion to the Ethereum Foundation bug bounty program Fixed in
0.11.14
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-45311
GHSA-vr26-jcq5-fjj8
RUSTSEC-2024-0373
Sep 03, 2024
Denial of service in quinn-proto when using `Endpoint::retry()`
High
Network
Low
None
None
SummaryAs of quinn-proto 0.11, it is possible for a server to
The former situation was observed in a real application, while the latter is only theoretical. DetailsLocation of panic: https://github.com/quinn-rs/quinn/blob/bb02a12a8435a7732a1d762783eeacbb7e50418e/quinn-proto/src/endpoint.rs#L213 ImpactDenial of service for internet-facing server Fixed in
0.11.7
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.11.6
unknown
Dependencies (16)
+ 8 more
Changelog
Compare changes
|
|
0.11.5
unknown
yanked
3 CVEs
CVE-2026-25800
GHSA-4w2j-m93h-cj5j
RUSTSEC-2026-0185
Jul 24, 2026
Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassembly
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryThe Fixed in
0.11.15
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-31812
GHSA-6xvm-j4wr-6v98
RUSTSEC-2026-0037
Mar 11, 2026
Quinn affected by unauthenticated remote DoS via panic in QUIC transport parameter parsing
High
Network
Low
None
None
SummaryA remote, unauthenticated attacker can trigger a denial of service in applications using vulnerable DetailsThe issue is panic-on-untrusted-input in QUIC transport parameter parsing.
In Observed output:
PoCReproduces against the upstream Quinn server example.
Observed output
ImpactVulnerability type: Remote Denial of Service (panic/crash)
Attack requirements: Network reachability to UDP QUIC listener
Authentication/privileges: None
Who is impacted: Any server/application using affected This vulnerability was originally submitted by @revofusion to the Ethereum Foundation bug bounty program Fixed in
0.11.14
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-45311
GHSA-vr26-jcq5-fjj8
RUSTSEC-2024-0373
Sep 03, 2024
Denial of service in quinn-proto when using `Endpoint::retry()`
High
Network
Low
None
None
SummaryAs of quinn-proto 0.11, it is possible for a server to
The former situation was observed in a real application, while the latter is only theoretical. DetailsLocation of panic: https://github.com/quinn-rs/quinn/blob/bb02a12a8435a7732a1d762783eeacbb7e50418e/quinn-proto/src/endpoint.rs#L213 ImpactDenial of service for internet-facing server Fixed in
0.11.7
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.11.5
unknown
yanked
Dependencies (16)
+ 8 more
Changelog
Compare changes
|
|
0.11.4
unknown
yanked
3 CVEs
CVE-2026-25800
GHSA-4w2j-m93h-cj5j
RUSTSEC-2026-0185
Jul 24, 2026
Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassembly
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryThe Fixed in
0.11.15
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-31812
GHSA-6xvm-j4wr-6v98
RUSTSEC-2026-0037
Mar 11, 2026
Quinn affected by unauthenticated remote DoS via panic in QUIC transport parameter parsing
High
Network
Low
None
None
SummaryA remote, unauthenticated attacker can trigger a denial of service in applications using vulnerable DetailsThe issue is panic-on-untrusted-input in QUIC transport parameter parsing.
In Observed output:
PoCReproduces against the upstream Quinn server example.
Observed output
ImpactVulnerability type: Remote Denial of Service (panic/crash)
Attack requirements: Network reachability to UDP QUIC listener
Authentication/privileges: None
Who is impacted: Any server/application using affected This vulnerability was originally submitted by @revofusion to the Ethereum Foundation bug bounty program Fixed in
0.11.14
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-45311
GHSA-vr26-jcq5-fjj8
RUSTSEC-2024-0373
Sep 03, 2024
Denial of service in quinn-proto when using `Endpoint::retry()`
High
Network
Low
None
None
SummaryAs of quinn-proto 0.11, it is possible for a server to
The former situation was observed in a real application, while the latter is only theoretical. DetailsLocation of panic: https://github.com/quinn-rs/quinn/blob/bb02a12a8435a7732a1d762783eeacbb7e50418e/quinn-proto/src/endpoint.rs#L213 ImpactDenial of service for internet-facing server Fixed in
0.11.7
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.11.4
unknown
yanked
Dependencies (16)
+ 8 more
Changelog
Compare changes
|
|
0.11.3
unknown
3 CVEs
CVE-2026-25800
GHSA-4w2j-m93h-cj5j
RUSTSEC-2026-0185
Jul 24, 2026
Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassembly
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryThe Fixed in
0.11.15
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-31812
GHSA-6xvm-j4wr-6v98
RUSTSEC-2026-0037
Mar 11, 2026
Quinn affected by unauthenticated remote DoS via panic in QUIC transport parameter parsing
High
Network
Low
None
None
SummaryA remote, unauthenticated attacker can trigger a denial of service in applications using vulnerable DetailsThe issue is panic-on-untrusted-input in QUIC transport parameter parsing.
In Observed output:
PoCReproduces against the upstream Quinn server example.
Observed output
ImpactVulnerability type: Remote Denial of Service (panic/crash)
Attack requirements: Network reachability to UDP QUIC listener
Authentication/privileges: None
Who is impacted: Any server/application using affected This vulnerability was originally submitted by @revofusion to the Ethereum Foundation bug bounty program Fixed in
0.11.14
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-45311
GHSA-vr26-jcq5-fjj8
RUSTSEC-2024-0373
Sep 03, 2024
Denial of service in quinn-proto when using `Endpoint::retry()`
High
Network
Low
None
None
SummaryAs of quinn-proto 0.11, it is possible for a server to
The former situation was observed in a real application, while the latter is only theoretical. DetailsLocation of panic: https://github.com/quinn-rs/quinn/blob/bb02a12a8435a7732a1d762783eeacbb7e50418e/quinn-proto/src/endpoint.rs#L213 ImpactDenial of service for internet-facing server Fixed in
0.11.7
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.11.3
unknown
Dependencies (16)
+ 8 more
Changelog
Compare changes
|
|
0.11.2
unknown
3 CVEs
CVE-2026-25800
GHSA-4w2j-m93h-cj5j
RUSTSEC-2026-0185
Jul 24, 2026
Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassembly
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryThe Fixed in
0.11.15
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-31812
GHSA-6xvm-j4wr-6v98
RUSTSEC-2026-0037
Mar 11, 2026
Quinn affected by unauthenticated remote DoS via panic in QUIC transport parameter parsing
High
Network
Low
None
None
SummaryA remote, unauthenticated attacker can trigger a denial of service in applications using vulnerable DetailsThe issue is panic-on-untrusted-input in QUIC transport parameter parsing.
In Observed output:
PoCReproduces against the upstream Quinn server example.
Observed output
ImpactVulnerability type: Remote Denial of Service (panic/crash)
Attack requirements: Network reachability to UDP QUIC listener
Authentication/privileges: None
Who is impacted: Any server/application using affected This vulnerability was originally submitted by @revofusion to the Ethereum Foundation bug bounty program Fixed in
0.11.14
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-45311
GHSA-vr26-jcq5-fjj8
RUSTSEC-2024-0373
Sep 03, 2024
Denial of service in quinn-proto when using `Endpoint::retry()`
High
Network
Low
None
None
SummaryAs of quinn-proto 0.11, it is possible for a server to
The former situation was observed in a real application, while the latter is only theoretical. DetailsLocation of panic: https://github.com/quinn-rs/quinn/blob/bb02a12a8435a7732a1d762783eeacbb7e50418e/quinn-proto/src/endpoint.rs#L213 ImpactDenial of service for internet-facing server Fixed in
0.11.7
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.11.2
unknown
Dependencies (16)
+ 8 more
Changelog
Compare changes
|
|
0.11.1
unknown
3 CVEs
CVE-2026-25800
GHSA-4w2j-m93h-cj5j
RUSTSEC-2026-0185
Jul 24, 2026
Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassembly
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryThe Fixed in
0.11.15
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-31812
GHSA-6xvm-j4wr-6v98
RUSTSEC-2026-0037
Mar 11, 2026
Quinn affected by unauthenticated remote DoS via panic in QUIC transport parameter parsing
High
Network
Low
None
None
SummaryA remote, unauthenticated attacker can trigger a denial of service in applications using vulnerable DetailsThe issue is panic-on-untrusted-input in QUIC transport parameter parsing.
In Observed output:
PoCReproduces against the upstream Quinn server example.
Observed output
ImpactVulnerability type: Remote Denial of Service (panic/crash)
Attack requirements: Network reachability to UDP QUIC listener
Authentication/privileges: None
Who is impacted: Any server/application using affected This vulnerability was originally submitted by @revofusion to the Ethereum Foundation bug bounty program Fixed in
0.11.14
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-45311
GHSA-vr26-jcq5-fjj8
RUSTSEC-2024-0373
Sep 03, 2024
Denial of service in quinn-proto when using `Endpoint::retry()`
High
Network
Low
None
None
SummaryAs of quinn-proto 0.11, it is possible for a server to
The former situation was observed in a real application, while the latter is only theoretical. DetailsLocation of panic: https://github.com/quinn-rs/quinn/blob/bb02a12a8435a7732a1d762783eeacbb7e50418e/quinn-proto/src/endpoint.rs#L213 ImpactDenial of service for internet-facing server Fixed in
0.11.7
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.11.1
unknown
Dependencies (16)
+ 8 more
Changelog
Compare changes
|
|
0.11.0
unknown
3 CVEs
CVE-2026-25800
GHSA-4w2j-m93h-cj5j
RUSTSEC-2026-0185
Jul 24, 2026
Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassembly
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryThe Fixed in
0.11.15
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-31812
GHSA-6xvm-j4wr-6v98
RUSTSEC-2026-0037
Mar 11, 2026
Quinn affected by unauthenticated remote DoS via panic in QUIC transport parameter parsing
High
Network
Low
None
None
SummaryA remote, unauthenticated attacker can trigger a denial of service in applications using vulnerable DetailsThe issue is panic-on-untrusted-input in QUIC transport parameter parsing.
In Observed output:
PoCReproduces against the upstream Quinn server example.
Observed output
ImpactVulnerability type: Remote Denial of Service (panic/crash)
Attack requirements: Network reachability to UDP QUIC listener
Authentication/privileges: None
Who is impacted: Any server/application using affected This vulnerability was originally submitted by @revofusion to the Ethereum Foundation bug bounty program Fixed in
0.11.14
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-45311
GHSA-vr26-jcq5-fjj8
RUSTSEC-2024-0373
Sep 03, 2024
Denial of service in quinn-proto when using `Endpoint::retry()`
High
Network
Low
None
None
SummaryAs of quinn-proto 0.11, it is possible for a server to
The former situation was observed in a real application, while the latter is only theoretical. DetailsLocation of panic: https://github.com/quinn-rs/quinn/blob/bb02a12a8435a7732a1d762783eeacbb7e50418e/quinn-proto/src/endpoint.rs#L213 ImpactDenial of service for internet-facing server Fixed in
0.11.7
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.11.0
unknown
Dependencies (16)
+ 8 more
Changelog
Compare changes
|
|
0.10.6
unknown
2 CVEs
CVE-2026-25800
GHSA-4w2j-m93h-cj5j
RUSTSEC-2026-0185
Jul 24, 2026
Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassembly
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryThe Fixed in
0.11.15
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-31812
GHSA-6xvm-j4wr-6v98
RUSTSEC-2026-0037
Mar 11, 2026
Quinn affected by unauthenticated remote DoS via panic in QUIC transport parameter parsing
High
Network
Low
None
None
SummaryA remote, unauthenticated attacker can trigger a denial of service in applications using vulnerable DetailsThe issue is panic-on-untrusted-input in QUIC transport parameter parsing.
In Observed output:
PoCReproduces against the upstream Quinn server example.
Observed output
ImpactVulnerability type: Remote Denial of Service (panic/crash)
Attack requirements: Network reachability to UDP QUIC listener
Authentication/privileges: None
Who is impacted: Any server/application using affected This vulnerability was originally submitted by @revofusion to the Ethereum Foundation bug bounty program Fixed in
0.11.14
References Updated Sep 10, 2026 · Source: OSV.dev |
0.10.6
unknown
Dependencies (16)
+ 8 more
Changelog
Compare changes
|
|
0.9.6
unknown
2 CVEs
CVE-2026-25800
GHSA-4w2j-m93h-cj5j
RUSTSEC-2026-0185
Jul 24, 2026
Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassembly
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryThe Fixed in
0.11.15
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-31812
GHSA-6xvm-j4wr-6v98
RUSTSEC-2026-0037
Mar 11, 2026
Quinn affected by unauthenticated remote DoS via panic in QUIC transport parameter parsing
High
Network
Low
None
None
SummaryA remote, unauthenticated attacker can trigger a denial of service in applications using vulnerable DetailsThe issue is panic-on-untrusted-input in QUIC transport parameter parsing.
In Observed output:
PoCReproduces against the upstream Quinn server example.
Observed output
ImpactVulnerability type: Remote Denial of Service (panic/crash)
Attack requirements: Network reachability to UDP QUIC listener
Authentication/privileges: None
Who is impacted: Any server/application using affected This vulnerability was originally submitted by @revofusion to the Ethereum Foundation bug bounty program Fixed in
0.11.14
References Updated Sep 10, 2026 · Source: OSV.dev |
0.9.6
unknown
Dependencies (17)
+ 9 more
Changelog
Compare changes
|
|
0.10.5
unknown
2 CVEs
CVE-2026-25800
GHSA-4w2j-m93h-cj5j
RUSTSEC-2026-0185
Jul 24, 2026
Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassembly
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryThe Fixed in
0.11.15
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-31812
GHSA-6xvm-j4wr-6v98
RUSTSEC-2026-0037
Mar 11, 2026
Quinn affected by unauthenticated remote DoS via panic in QUIC transport parameter parsing
High
Network
Low
None
None
SummaryA remote, unauthenticated attacker can trigger a denial of service in applications using vulnerable DetailsThe issue is panic-on-untrusted-input in QUIC transport parameter parsing.
In Observed output:
PoCReproduces against the upstream Quinn server example.
Observed output
ImpactVulnerability type: Remote Denial of Service (panic/crash)
Attack requirements: Network reachability to UDP QUIC listener
Authentication/privileges: None
Who is impacted: Any server/application using affected This vulnerability was originally submitted by @revofusion to the Ethereum Foundation bug bounty program Fixed in
0.11.14
References Updated Sep 10, 2026 · Source: OSV.dev |
0.10.5
unknown
Dependencies (16)
+ 8 more
Changelog
Compare changes
|
|
0.9.5
unknown
2 CVEs
CVE-2026-25800
GHSA-4w2j-m93h-cj5j
RUSTSEC-2026-0185
Jul 24, 2026
Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassembly
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryThe Fixed in
0.11.15
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-31812
GHSA-6xvm-j4wr-6v98
RUSTSEC-2026-0037
Mar 11, 2026
Quinn affected by unauthenticated remote DoS via panic in QUIC transport parameter parsing
High
Network
Low
None
None
SummaryA remote, unauthenticated attacker can trigger a denial of service in applications using vulnerable DetailsThe issue is panic-on-untrusted-input in QUIC transport parameter parsing.
In Observed output:
PoCReproduces against the upstream Quinn server example.
Observed output
ImpactVulnerability type: Remote Denial of Service (panic/crash)
Attack requirements: Network reachability to UDP QUIC listener
Authentication/privileges: None
Who is impacted: Any server/application using affected This vulnerability was originally submitted by @revofusion to the Ethereum Foundation bug bounty program Fixed in
0.11.14
References Updated Sep 10, 2026 · Source: OSV.dev |
0.9.5
unknown
Dependencies (17)
+ 9 more
Changelog
Compare changes
|
|
0.10.4
unknown
2 CVEs
CVE-2026-25800
GHSA-4w2j-m93h-cj5j
RUSTSEC-2026-0185
Jul 24, 2026
Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassembly
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryThe Fixed in
0.11.15
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-31812
GHSA-6xvm-j4wr-6v98
RUSTSEC-2026-0037
Mar 11, 2026
Quinn affected by unauthenticated remote DoS via panic in QUIC transport parameter parsing
High
Network
Low
None
None
SummaryA remote, unauthenticated attacker can trigger a denial of service in applications using vulnerable DetailsThe issue is panic-on-untrusted-input in QUIC transport parameter parsing.
In Observed output:
PoCReproduces against the upstream Quinn server example.
Observed output
ImpactVulnerability type: Remote Denial of Service (panic/crash)
Attack requirements: Network reachability to UDP QUIC listener
Authentication/privileges: None
Who is impacted: Any server/application using affected This vulnerability was originally submitted by @revofusion to the Ethereum Foundation bug bounty program Fixed in
0.11.14
References Updated Sep 10, 2026 · Source: OSV.dev |
0.10.4
unknown
Dependencies (16)
+ 8 more
Changelog
Compare changes
|
|
0.10.3
unknown
2 CVEs
CVE-2026-25800
GHSA-4w2j-m93h-cj5j
RUSTSEC-2026-0185
Jul 24, 2026
Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassembly
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryThe Fixed in
0.11.15
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-31812
GHSA-6xvm-j4wr-6v98
RUSTSEC-2026-0037
Mar 11, 2026
Quinn affected by unauthenticated remote DoS via panic in QUIC transport parameter parsing
High
Network
Low
None
None
SummaryA remote, unauthenticated attacker can trigger a denial of service in applications using vulnerable DetailsThe issue is panic-on-untrusted-input in QUIC transport parameter parsing.
In Observed output:
PoCReproduces against the upstream Quinn server example.
Observed output
ImpactVulnerability type: Remote Denial of Service (panic/crash)
Attack requirements: Network reachability to UDP QUIC listener
Authentication/privileges: None
Who is impacted: Any server/application using affected This vulnerability was originally submitted by @revofusion to the Ethereum Foundation bug bounty program Fixed in
0.11.14
References Updated Sep 10, 2026 · Source: OSV.dev |
0.10.3
unknown
Dependencies (16)
+ 8 more
Changelog
Compare changes
|
|
0.10.2
unknown
2 CVEs
CVE-2026-25800
GHSA-4w2j-m93h-cj5j
RUSTSEC-2026-0185
Jul 24, 2026
Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassembly
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryThe Fixed in
0.11.15
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-31812
GHSA-6xvm-j4wr-6v98
RUSTSEC-2026-0037
Mar 11, 2026
Quinn affected by unauthenticated remote DoS via panic in QUIC transport parameter parsing
High
Network
Low
None
None
SummaryA remote, unauthenticated attacker can trigger a denial of service in applications using vulnerable DetailsThe issue is panic-on-untrusted-input in QUIC transport parameter parsing.
In Observed output:
PoCReproduces against the upstream Quinn server example.
Observed output
ImpactVulnerability type: Remote Denial of Service (panic/crash)
Attack requirements: Network reachability to UDP QUIC listener
Authentication/privileges: None
Who is impacted: Any server/application using affected This vulnerability was originally submitted by @revofusion to the Ethereum Foundation bug bounty program Fixed in
0.11.14
References Updated Sep 10, 2026 · Source: OSV.dev |
0.10.2
unknown
Dependencies (16)
+ 8 more
Changelog
Compare changes
|
|
0.9.4
unknown
3 CVEs
CVE-2026-25800
GHSA-4w2j-m93h-cj5j
RUSTSEC-2026-0185
Jul 24, 2026
Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassembly
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryThe Fixed in
0.11.15
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-31812
GHSA-6xvm-j4wr-6v98
RUSTSEC-2026-0037
Mar 11, 2026
Quinn affected by unauthenticated remote DoS via panic in QUIC transport parameter parsing
High
Network
Low
None
None
SummaryA remote, unauthenticated attacker can trigger a denial of service in applications using vulnerable DetailsThe issue is panic-on-untrusted-input in QUIC transport parameter parsing.
In Observed output:
PoCReproduces against the upstream Quinn server example.
Observed output
ImpactVulnerability type: Remote Denial of Service (panic/crash)
Attack requirements: Network reachability to UDP QUIC listener
Authentication/privileges: None
Who is impacted: Any server/application using affected This vulnerability was originally submitted by @revofusion to the Ethereum Foundation bug bounty program Fixed in
0.11.14
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-42805
GHSA-q8wc-j5m9-27w3
RUSTSEC-2023-0063
Sep 21, 2023
Denial of Service issue in quinn-proto
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactReceiving unknown QUIC frames in a QUIC packet could result in a panic. PatchesThe problem has been fixed in 0.9.5 and 0.10.5 maintenance releases. ReferencesFixed in https://github.com/quinn-rs/quinn/pull/1667, backported in https://github.com/quinn-rs/quinn/pull/1668 and https://github.com/quinn-rs/quinn/pull/1669. Fixed in
0.9.5
References Updated Sep 10, 2026 · Source: OSV.dev |
0.9.4
unknown
Dependencies (17)
+ 9 more
Changelog
Compare changes
|
|
0.10.1
unknown
2 CVEs
CVE-2026-25800
GHSA-4w2j-m93h-cj5j
RUSTSEC-2026-0185
Jul 24, 2026
Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassembly
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryThe Fixed in
0.11.15
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-31812
GHSA-6xvm-j4wr-6v98
RUSTSEC-2026-0037
Mar 11, 2026
Quinn affected by unauthenticated remote DoS via panic in QUIC transport parameter parsing
High
Network
Low
None
None
SummaryA remote, unauthenticated attacker can trigger a denial of service in applications using vulnerable DetailsThe issue is panic-on-untrusted-input in QUIC transport parameter parsing.
In Observed output:
PoCReproduces against the upstream Quinn server example.
Observed output
ImpactVulnerability type: Remote Denial of Service (panic/crash)
Attack requirements: Network reachability to UDP QUIC listener
Authentication/privileges: None
Who is impacted: Any server/application using affected This vulnerability was originally submitted by @revofusion to the Ethereum Foundation bug bounty program Fixed in
0.11.14
References Updated Sep 10, 2026 · Source: OSV.dev |
0.10.1
unknown
Dependencies (16)
+ 8 more
Changelog
Compare changes
|
|
0.10.0
unknown
2 CVEs
CVE-2026-25800
GHSA-4w2j-m93h-cj5j
RUSTSEC-2026-0185
Jul 24, 2026
Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassembly
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryThe Fixed in
0.11.15
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-31812
GHSA-6xvm-j4wr-6v98
RUSTSEC-2026-0037
Mar 11, 2026
Quinn affected by unauthenticated remote DoS via panic in QUIC transport parameter parsing
High
Network
Low
None
None
SummaryA remote, unauthenticated attacker can trigger a denial of service in applications using vulnerable DetailsThe issue is panic-on-untrusted-input in QUIC transport parameter parsing.
In Observed output:
PoCReproduces against the upstream Quinn server example.
Observed output
ImpactVulnerability type: Remote Denial of Service (panic/crash)
Attack requirements: Network reachability to UDP QUIC listener
Authentication/privileges: None
Who is impacted: Any server/application using affected This vulnerability was originally submitted by @revofusion to the Ethereum Foundation bug bounty program Fixed in
0.11.14
References Updated Sep 10, 2026 · Source: OSV.dev |
0.10.0
unknown
Dependencies (17)
+ 9 more
Changelog
Compare changes
|
|
0.9.3
unknown
3 CVEs
CVE-2026-25800
GHSA-4w2j-m93h-cj5j
RUSTSEC-2026-0185
Jul 24, 2026
Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassembly
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryThe Fixed in
0.11.15
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-31812
GHSA-6xvm-j4wr-6v98
RUSTSEC-2026-0037
Mar 11, 2026
Quinn affected by unauthenticated remote DoS via panic in QUIC transport parameter parsing
High
Network
Low
None
None
SummaryA remote, unauthenticated attacker can trigger a denial of service in applications using vulnerable DetailsThe issue is panic-on-untrusted-input in QUIC transport parameter parsing.
In Observed output:
PoCReproduces against the upstream Quinn server example.
Observed output
ImpactVulnerability type: Remote Denial of Service (panic/crash)
Attack requirements: Network reachability to UDP QUIC listener
Authentication/privileges: None
Who is impacted: Any server/application using affected This vulnerability was originally submitted by @revofusion to the Ethereum Foundation bug bounty program Fixed in
0.11.14
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-42805
GHSA-q8wc-j5m9-27w3
RUSTSEC-2023-0063
Sep 21, 2023
Denial of Service issue in quinn-proto
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactReceiving unknown QUIC frames in a QUIC packet could result in a panic. PatchesThe problem has been fixed in 0.9.5 and 0.10.5 maintenance releases. ReferencesFixed in https://github.com/quinn-rs/quinn/pull/1667, backported in https://github.com/quinn-rs/quinn/pull/1668 and https://github.com/quinn-rs/quinn/pull/1669. Fixed in
0.9.5
References Updated Sep 10, 2026 · Source: OSV.dev |
0.9.3
unknown
Dependencies (17)
+ 9 more
Changelog
Compare changes
|
|
0.9.2
unknown
3 CVEs
CVE-2026-25800
GHSA-4w2j-m93h-cj5j
RUSTSEC-2026-0185
Jul 24, 2026
Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassembly
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryThe Fixed in
0.11.15
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-31812
GHSA-6xvm-j4wr-6v98
RUSTSEC-2026-0037
Mar 11, 2026
Quinn affected by unauthenticated remote DoS via panic in QUIC transport parameter parsing
High
Network
Low
None
None
SummaryA remote, unauthenticated attacker can trigger a denial of service in applications using vulnerable DetailsThe issue is panic-on-untrusted-input in QUIC transport parameter parsing.
In Observed output:
PoCReproduces against the upstream Quinn server example.
Observed output
ImpactVulnerability type: Remote Denial of Service (panic/crash)
Attack requirements: Network reachability to UDP QUIC listener
Authentication/privileges: None
Who is impacted: Any server/application using affected This vulnerability was originally submitted by @revofusion to the Ethereum Foundation bug bounty program Fixed in
0.11.14
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-42805
GHSA-q8wc-j5m9-27w3
RUSTSEC-2023-0063
Sep 21, 2023
Denial of Service issue in quinn-proto
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactReceiving unknown QUIC frames in a QUIC packet could result in a panic. PatchesThe problem has been fixed in 0.9.5 and 0.10.5 maintenance releases. ReferencesFixed in https://github.com/quinn-rs/quinn/pull/1667, backported in https://github.com/quinn-rs/quinn/pull/1668 and https://github.com/quinn-rs/quinn/pull/1669. Fixed in
0.9.5
References Updated Sep 10, 2026 · Source: OSV.dev |
0.9.2
unknown
Dependencies (17)
+ 9 more
Changelog
Compare changes
|
|
0.9.1
unknown
3 CVEs
CVE-2026-25800
GHSA-4w2j-m93h-cj5j
RUSTSEC-2026-0185
Jul 24, 2026
Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassembly
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryThe Fixed in
0.11.15
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-31812
GHSA-6xvm-j4wr-6v98
RUSTSEC-2026-0037
Mar 11, 2026
Quinn affected by unauthenticated remote DoS via panic in QUIC transport parameter parsing
High
Network
Low
None
None
SummaryA remote, unauthenticated attacker can trigger a denial of service in applications using vulnerable DetailsThe issue is panic-on-untrusted-input in QUIC transport parameter parsing.
In Observed output:
PoCReproduces against the upstream Quinn server example.
Observed output
ImpactVulnerability type: Remote Denial of Service (panic/crash)
Attack requirements: Network reachability to UDP QUIC listener
Authentication/privileges: None
Who is impacted: Any server/application using affected This vulnerability was originally submitted by @revofusion to the Ethereum Foundation bug bounty program Fixed in
0.11.14
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-42805
GHSA-q8wc-j5m9-27w3
RUSTSEC-2023-0063
Sep 21, 2023
Denial of Service issue in quinn-proto
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactReceiving unknown QUIC frames in a QUIC packet could result in a panic. PatchesThe problem has been fixed in 0.9.5 and 0.10.5 maintenance releases. ReferencesFixed in https://github.com/quinn-rs/quinn/pull/1667, backported in https://github.com/quinn-rs/quinn/pull/1668 and https://github.com/quinn-rs/quinn/pull/1669. Fixed in
0.9.5
References Updated Sep 10, 2026 · Source: OSV.dev |
0.9.1
unknown
Dependencies (17)
+ 9 more
Changelog
Compare changes
|
|
0.9.0
unknown
3 CVEs
CVE-2026-25800
GHSA-4w2j-m93h-cj5j
RUSTSEC-2026-0185
Jul 24, 2026
Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassembly
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryThe Fixed in
0.11.15
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-31812
GHSA-6xvm-j4wr-6v98
RUSTSEC-2026-0037
Mar 11, 2026
Quinn affected by unauthenticated remote DoS via panic in QUIC transport parameter parsing
High
Network
Low
None
None
SummaryA remote, unauthenticated attacker can trigger a denial of service in applications using vulnerable DetailsThe issue is panic-on-untrusted-input in QUIC transport parameter parsing.
In Observed output:
PoCReproduces against the upstream Quinn server example.
Observed output
ImpactVulnerability type: Remote Denial of Service (panic/crash)
Attack requirements: Network reachability to UDP QUIC listener
Authentication/privileges: None
Who is impacted: Any server/application using affected This vulnerability was originally submitted by @revofusion to the Ethereum Foundation bug bounty program Fixed in
0.11.14
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-42805
GHSA-q8wc-j5m9-27w3
RUSTSEC-2023-0063
Sep 21, 2023
Denial of Service issue in quinn-proto
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactReceiving unknown QUIC frames in a QUIC packet could result in a panic. PatchesThe problem has been fixed in 0.9.5 and 0.10.5 maintenance releases. ReferencesFixed in https://github.com/quinn-rs/quinn/pull/1667, backported in https://github.com/quinn-rs/quinn/pull/1668 and https://github.com/quinn-rs/quinn/pull/1669. Fixed in
0.9.5
References Updated Sep 10, 2026 · Source: OSV.dev |
0.9.0
unknown
Dependencies (17)
+ 9 more
Changelog
Compare changes
|
|
0.8.4
unknown
3 CVEs
CVE-2026-25800
GHSA-4w2j-m93h-cj5j
RUSTSEC-2026-0185
Jul 24, 2026
Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassembly
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryThe Fixed in
0.11.15
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-31812
GHSA-6xvm-j4wr-6v98
RUSTSEC-2026-0037
Mar 11, 2026
Quinn affected by unauthenticated remote DoS via panic in QUIC transport parameter parsing
High
Network
Low
None
None
SummaryA remote, unauthenticated attacker can trigger a denial of service in applications using vulnerable DetailsThe issue is panic-on-untrusted-input in QUIC transport parameter parsing.
In Observed output:
PoCReproduces against the upstream Quinn server example.
Observed output
ImpactVulnerability type: Remote Denial of Service (panic/crash)
Attack requirements: Network reachability to UDP QUIC listener
Authentication/privileges: None
Who is impacted: Any server/application using affected This vulnerability was originally submitted by @revofusion to the Ethereum Foundation bug bounty program Fixed in
0.11.14
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-42805
GHSA-q8wc-j5m9-27w3
RUSTSEC-2023-0063
Sep 21, 2023
Denial of Service issue in quinn-proto
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactReceiving unknown QUIC frames in a QUIC packet could result in a panic. PatchesThe problem has been fixed in 0.9.5 and 0.10.5 maintenance releases. ReferencesFixed in https://github.com/quinn-rs/quinn/pull/1667, backported in https://github.com/quinn-rs/quinn/pull/1668 and https://github.com/quinn-rs/quinn/pull/1669. Fixed in
0.9.5
References Updated Sep 10, 2026 · Source: OSV.dev |
0.8.4
unknown
Dependencies (18)
+ 10 more
Changelog
Compare changes
|
|
0.8.3
unknown
3 CVEs
CVE-2026-25800
GHSA-4w2j-m93h-cj5j
RUSTSEC-2026-0185
Jul 24, 2026
Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassembly
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryThe Fixed in
0.11.15
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-31812
GHSA-6xvm-j4wr-6v98
RUSTSEC-2026-0037
Mar 11, 2026
Quinn affected by unauthenticated remote DoS via panic in QUIC transport parameter parsing
High
Network
Low
None
None
SummaryA remote, unauthenticated attacker can trigger a denial of service in applications using vulnerable DetailsThe issue is panic-on-untrusted-input in QUIC transport parameter parsing.
In Observed output:
PoCReproduces against the upstream Quinn server example.
Observed output
ImpactVulnerability type: Remote Denial of Service (panic/crash)
Attack requirements: Network reachability to UDP QUIC listener
Authentication/privileges: None
Who is impacted: Any server/application using affected This vulnerability was originally submitted by @revofusion to the Ethereum Foundation bug bounty program Fixed in
0.11.14
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-42805
GHSA-q8wc-j5m9-27w3
RUSTSEC-2023-0063
Sep 21, 2023
Denial of Service issue in quinn-proto
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactReceiving unknown QUIC frames in a QUIC packet could result in a panic. PatchesThe problem has been fixed in 0.9.5 and 0.10.5 maintenance releases. ReferencesFixed in https://github.com/quinn-rs/quinn/pull/1667, backported in https://github.com/quinn-rs/quinn/pull/1668 and https://github.com/quinn-rs/quinn/pull/1669. Fixed in
0.9.5
References Updated Sep 10, 2026 · Source: OSV.dev |
0.8.3
unknown
Dependencies (18)
+ 10 more
Changelog
Compare changes
|
|
0.8.2
unknown
3 CVEs
CVE-2026-25800
GHSA-4w2j-m93h-cj5j
RUSTSEC-2026-0185
Jul 24, 2026
Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassembly
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryThe Fixed in
0.11.15
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-31812
GHSA-6xvm-j4wr-6v98
RUSTSEC-2026-0037
Mar 11, 2026
Quinn affected by unauthenticated remote DoS via panic in QUIC transport parameter parsing
High
Network
Low
None
None
SummaryA remote, unauthenticated attacker can trigger a denial of service in applications using vulnerable DetailsThe issue is panic-on-untrusted-input in QUIC transport parameter parsing.
In Observed output:
PoCReproduces against the upstream Quinn server example.
Observed output
ImpactVulnerability type: Remote Denial of Service (panic/crash)
Attack requirements: Network reachability to UDP QUIC listener
Authentication/privileges: None
Who is impacted: Any server/application using affected This vulnerability was originally submitted by @revofusion to the Ethereum Foundation bug bounty program Fixed in
0.11.14
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-42805
GHSA-q8wc-j5m9-27w3
RUSTSEC-2023-0063
Sep 21, 2023
Denial of Service issue in quinn-proto
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactReceiving unknown QUIC frames in a QUIC packet could result in a panic. PatchesThe problem has been fixed in 0.9.5 and 0.10.5 maintenance releases. ReferencesFixed in https://github.com/quinn-rs/quinn/pull/1667, backported in https://github.com/quinn-rs/quinn/pull/1668 and https://github.com/quinn-rs/quinn/pull/1669. Fixed in
0.9.5
References Updated Sep 10, 2026 · Source: OSV.dev |
0.8.2
unknown
Dependencies (18)
+ 10 more
Changelog
Compare changes
|
|
0.8.1
unknown
3 CVEs
CVE-2026-25800
GHSA-4w2j-m93h-cj5j
RUSTSEC-2026-0185
Jul 24, 2026
Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassembly
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryThe Fixed in
0.11.15
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-31812
GHSA-6xvm-j4wr-6v98
RUSTSEC-2026-0037
Mar 11, 2026
Quinn affected by unauthenticated remote DoS via panic in QUIC transport parameter parsing
High
Network
Low
None
None
SummaryA remote, unauthenticated attacker can trigger a denial of service in applications using vulnerable DetailsThe issue is panic-on-untrusted-input in QUIC transport parameter parsing.
In Observed output:
PoCReproduces against the upstream Quinn server example.
Observed output
ImpactVulnerability type: Remote Denial of Service (panic/crash)
Attack requirements: Network reachability to UDP QUIC listener
Authentication/privileges: None
Who is impacted: Any server/application using affected This vulnerability was originally submitted by @revofusion to the Ethereum Foundation bug bounty program Fixed in
0.11.14
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-42805
GHSA-q8wc-j5m9-27w3
RUSTSEC-2023-0063
Sep 21, 2023
Denial of Service issue in quinn-proto
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactReceiving unknown QUIC frames in a QUIC packet could result in a panic. PatchesThe problem has been fixed in 0.9.5 and 0.10.5 maintenance releases. ReferencesFixed in https://github.com/quinn-rs/quinn/pull/1667, backported in https://github.com/quinn-rs/quinn/pull/1668 and https://github.com/quinn-rs/quinn/pull/1669. Fixed in
0.9.5
References Updated Sep 10, 2026 · Source: OSV.dev |
0.8.1
unknown
Dependencies (18)
+ 10 more
Changelog
Compare changes
|
|
0.8.0
unknown
3 CVEs
CVE-2026-25800
GHSA-4w2j-m93h-cj5j
RUSTSEC-2026-0185
Jul 24, 2026
Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassembly
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryThe Fixed in
0.11.15
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-31812
GHSA-6xvm-j4wr-6v98
RUSTSEC-2026-0037
Mar 11, 2026
Quinn affected by unauthenticated remote DoS via panic in QUIC transport parameter parsing
High
Network
Low
None
None
SummaryA remote, unauthenticated attacker can trigger a denial of service in applications using vulnerable DetailsThe issue is panic-on-untrusted-input in QUIC transport parameter parsing.
In Observed output:
PoCReproduces against the upstream Quinn server example.
Observed output
ImpactVulnerability type: Remote Denial of Service (panic/crash)
Attack requirements: Network reachability to UDP QUIC listener
Authentication/privileges: None
Who is impacted: Any server/application using affected This vulnerability was originally submitted by @revofusion to the Ethereum Foundation bug bounty program Fixed in
0.11.14
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-42805
GHSA-q8wc-j5m9-27w3
RUSTSEC-2023-0063
Sep 21, 2023
Denial of Service issue in quinn-proto
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactReceiving unknown QUIC frames in a QUIC packet could result in a panic. PatchesThe problem has been fixed in 0.9.5 and 0.10.5 maintenance releases. ReferencesFixed in https://github.com/quinn-rs/quinn/pull/1667, backported in https://github.com/quinn-rs/quinn/pull/1668 and https://github.com/quinn-rs/quinn/pull/1669. Fixed in
0.9.5
References Updated Sep 10, 2026 · Source: OSV.dev |
0.8.0
unknown
Dependencies (18)
+ 10 more
Changelog
Compare changes
|
|
0.7.3
unknown
3 CVEs
CVE-2026-25800
GHSA-4w2j-m93h-cj5j
RUSTSEC-2026-0185
Jul 24, 2026
Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassembly
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryThe Fixed in
0.11.15
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-31812
GHSA-6xvm-j4wr-6v98
RUSTSEC-2026-0037
Mar 11, 2026
Quinn affected by unauthenticated remote DoS via panic in QUIC transport parameter parsing
High
Network
Low
None
None
SummaryA remote, unauthenticated attacker can trigger a denial of service in applications using vulnerable DetailsThe issue is panic-on-untrusted-input in QUIC transport parameter parsing.
In Observed output:
PoCReproduces against the upstream Quinn server example.
Observed output
ImpactVulnerability type: Remote Denial of Service (panic/crash)
Attack requirements: Network reachability to UDP QUIC listener
Authentication/privileges: None
Who is impacted: Any server/application using affected This vulnerability was originally submitted by @revofusion to the Ethereum Foundation bug bounty program Fixed in
0.11.14
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-42805
GHSA-q8wc-j5m9-27w3
RUSTSEC-2023-0063
Sep 21, 2023
Denial of Service issue in quinn-proto
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactReceiving unknown QUIC frames in a QUIC packet could result in a panic. PatchesThe problem has been fixed in 0.9.5 and 0.10.5 maintenance releases. ReferencesFixed in https://github.com/quinn-rs/quinn/pull/1667, backported in https://github.com/quinn-rs/quinn/pull/1668 and https://github.com/quinn-rs/quinn/pull/1669. Fixed in
0.9.5
References Updated Sep 10, 2026 · Source: OSV.dev |
0.7.3
unknown
Dependencies (17)
+ 9 more
Changelog
Compare changes
|
|
0.7.2
unknown
3 CVEs
CVE-2026-25800
GHSA-4w2j-m93h-cj5j
RUSTSEC-2026-0185
Jul 24, 2026
Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassembly
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryThe Fixed in
0.11.15
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-31812
GHSA-6xvm-j4wr-6v98
RUSTSEC-2026-0037
Mar 11, 2026
Quinn affected by unauthenticated remote DoS via panic in QUIC transport parameter parsing
High
Network
Low
None
None
SummaryA remote, unauthenticated attacker can trigger a denial of service in applications using vulnerable DetailsThe issue is panic-on-untrusted-input in QUIC transport parameter parsing.
In Observed output:
PoCReproduces against the upstream Quinn server example.
Observed output
ImpactVulnerability type: Remote Denial of Service (panic/crash)
Attack requirements: Network reachability to UDP QUIC listener
Authentication/privileges: None
Who is impacted: Any server/application using affected This vulnerability was originally submitted by @revofusion to the Ethereum Foundation bug bounty program Fixed in
0.11.14
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-42805
GHSA-q8wc-j5m9-27w3
RUSTSEC-2023-0063
Sep 21, 2023
Denial of Service issue in quinn-proto
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactReceiving unknown QUIC frames in a QUIC packet could result in a panic. PatchesThe problem has been fixed in 0.9.5 and 0.10.5 maintenance releases. ReferencesFixed in https://github.com/quinn-rs/quinn/pull/1667, backported in https://github.com/quinn-rs/quinn/pull/1668 and https://github.com/quinn-rs/quinn/pull/1669. Fixed in
0.9.5
References Updated Sep 10, 2026 · Source: OSV.dev |
0.7.2
unknown
Dependencies (17)
+ 9 more
Changelog
Compare changes
|
|
0.7.1
unknown
3 CVEs
CVE-2026-25800
GHSA-4w2j-m93h-cj5j
RUSTSEC-2026-0185
Jul 24, 2026
Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassembly
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryThe Fixed in
0.11.15
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-31812
GHSA-6xvm-j4wr-6v98
RUSTSEC-2026-0037
Mar 11, 2026
Quinn affected by unauthenticated remote DoS via panic in QUIC transport parameter parsing
High
Network
Low
None
None
SummaryA remote, unauthenticated attacker can trigger a denial of service in applications using vulnerable DetailsThe issue is panic-on-untrusted-input in QUIC transport parameter parsing.
In Observed output:
PoCReproduces against the upstream Quinn server example.
Observed output
ImpactVulnerability type: Remote Denial of Service (panic/crash)
Attack requirements: Network reachability to UDP QUIC listener
Authentication/privileges: None
Who is impacted: Any server/application using affected This vulnerability was originally submitted by @revofusion to the Ethereum Foundation bug bounty program Fixed in
0.11.14
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-42805
GHSA-q8wc-j5m9-27w3
RUSTSEC-2023-0063
Sep 21, 2023
Denial of Service issue in quinn-proto
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactReceiving unknown QUIC frames in a QUIC packet could result in a panic. PatchesThe problem has been fixed in 0.9.5 and 0.10.5 maintenance releases. ReferencesFixed in https://github.com/quinn-rs/quinn/pull/1667, backported in https://github.com/quinn-rs/quinn/pull/1668 and https://github.com/quinn-rs/quinn/pull/1669. Fixed in
0.9.5
References Updated Sep 10, 2026 · Source: OSV.dev |
0.7.1
unknown
Dependencies (17)
+ 9 more
Changelog
Compare changes
|
|
0.7.0
unknown
3 CVEs
CVE-2026-25800
GHSA-4w2j-m93h-cj5j
RUSTSEC-2026-0185
Jul 24, 2026
Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassembly
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryThe Fixed in
0.11.15
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-31812
GHSA-6xvm-j4wr-6v98
RUSTSEC-2026-0037
Mar 11, 2026
Quinn affected by unauthenticated remote DoS via panic in QUIC transport parameter parsing
High
Network
Low
None
None
SummaryA remote, unauthenticated attacker can trigger a denial of service in applications using vulnerable DetailsThe issue is panic-on-untrusted-input in QUIC transport parameter parsing.
In Observed output:
PoCReproduces against the upstream Quinn server example.
Observed output
ImpactVulnerability type: Remote Denial of Service (panic/crash)
Attack requirements: Network reachability to UDP QUIC listener
Authentication/privileges: None
Who is impacted: Any server/application using affected This vulnerability was originally submitted by @revofusion to the Ethereum Foundation bug bounty program Fixed in
0.11.14
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-42805
GHSA-q8wc-j5m9-27w3
RUSTSEC-2023-0063
Sep 21, 2023
Denial of Service issue in quinn-proto
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactReceiving unknown QUIC frames in a QUIC packet could result in a panic. PatchesThe problem has been fixed in 0.9.5 and 0.10.5 maintenance releases. ReferencesFixed in https://github.com/quinn-rs/quinn/pull/1667, backported in https://github.com/quinn-rs/quinn/pull/1668 and https://github.com/quinn-rs/quinn/pull/1669. Fixed in
0.9.5
References Updated Sep 10, 2026 · Source: OSV.dev |
0.7.0
unknown
Dependencies (17)
+ 9 more
Changelog
Compare changes
|
|
0.6.1
unknown
3 CVEs
CVE-2026-25800
GHSA-4w2j-m93h-cj5j
RUSTSEC-2026-0185
Jul 24, 2026
Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassembly
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryThe Fixed in
0.11.15
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-31812
GHSA-6xvm-j4wr-6v98
RUSTSEC-2026-0037
Mar 11, 2026
Quinn affected by unauthenticated remote DoS via panic in QUIC transport parameter parsing
High
Network
Low
None
None
SummaryA remote, unauthenticated attacker can trigger a denial of service in applications using vulnerable DetailsThe issue is panic-on-untrusted-input in QUIC transport parameter parsing.
In Observed output:
PoCReproduces against the upstream Quinn server example.
Observed output
ImpactVulnerability type: Remote Denial of Service (panic/crash)
Attack requirements: Network reachability to UDP QUIC listener
Authentication/privileges: None
Who is impacted: Any server/application using affected This vulnerability was originally submitted by @revofusion to the Ethereum Foundation bug bounty program Fixed in
0.11.14
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-42805
GHSA-q8wc-j5m9-27w3
RUSTSEC-2023-0063
Sep 21, 2023
Denial of Service issue in quinn-proto
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactReceiving unknown QUIC frames in a QUIC packet could result in a panic. PatchesThe problem has been fixed in 0.9.5 and 0.10.5 maintenance releases. ReferencesFixed in https://github.com/quinn-rs/quinn/pull/1667, backported in https://github.com/quinn-rs/quinn/pull/1668 and https://github.com/quinn-rs/quinn/pull/1669. Fixed in
0.9.5
References Updated Sep 10, 2026 · Source: OSV.dev |
0.6.1
unknown
Dependencies (15)
+ 7 more
Changelog
Compare changes
|
|
0.6.0
unknown
3 CVEs
CVE-2026-25800
GHSA-4w2j-m93h-cj5j
RUSTSEC-2026-0185
Jul 24, 2026
Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassembly
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryThe Fixed in
0.11.15
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-31812
GHSA-6xvm-j4wr-6v98
RUSTSEC-2026-0037
Mar 11, 2026
Quinn affected by unauthenticated remote DoS via panic in QUIC transport parameter parsing
High
Network
Low
None
None
SummaryA remote, unauthenticated attacker can trigger a denial of service in applications using vulnerable DetailsThe issue is panic-on-untrusted-input in QUIC transport parameter parsing.
In Observed output:
PoCReproduces against the upstream Quinn server example.
Observed output
ImpactVulnerability type: Remote Denial of Service (panic/crash)
Attack requirements: Network reachability to UDP QUIC listener
Authentication/privileges: None
Who is impacted: Any server/application using affected This vulnerability was originally submitted by @revofusion to the Ethereum Foundation bug bounty program Fixed in
0.11.14
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-42805
GHSA-q8wc-j5m9-27w3
RUSTSEC-2023-0063
Sep 21, 2023
Denial of Service issue in quinn-proto
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactReceiving unknown QUIC frames in a QUIC packet could result in a panic. PatchesThe problem has been fixed in 0.9.5 and 0.10.5 maintenance releases. ReferencesFixed in https://github.com/quinn-rs/quinn/pull/1667, backported in https://github.com/quinn-rs/quinn/pull/1668 and https://github.com/quinn-rs/quinn/pull/1669. Fixed in
0.9.5
References Updated Sep 10, 2026 · Source: OSV.dev |
0.6.0
unknown
Dependencies (15)
+ 7 more
Changelog
Compare changes
|
|
0.5.2
unknown
3 CVEs
CVE-2026-25800
GHSA-4w2j-m93h-cj5j
RUSTSEC-2026-0185
Jul 24, 2026
Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassembly
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryThe Fixed in
0.11.15
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-31812
GHSA-6xvm-j4wr-6v98
RUSTSEC-2026-0037
Mar 11, 2026
Quinn affected by unauthenticated remote DoS via panic in QUIC transport parameter parsing
High
Network
Low
None
None
SummaryA remote, unauthenticated attacker can trigger a denial of service in applications using vulnerable DetailsThe issue is panic-on-untrusted-input in QUIC transport parameter parsing.
In Observed output:
PoCReproduces against the upstream Quinn server example.
Observed output
ImpactVulnerability type: Remote Denial of Service (panic/crash)
Attack requirements: Network reachability to UDP QUIC listener
Authentication/privileges: None
Who is impacted: Any server/application using affected This vulnerability was originally submitted by @revofusion to the Ethereum Foundation bug bounty program Fixed in
0.11.14
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-42805
GHSA-q8wc-j5m9-27w3
RUSTSEC-2023-0063
Sep 21, 2023
Denial of Service issue in quinn-proto
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactReceiving unknown QUIC frames in a QUIC packet could result in a panic. PatchesThe problem has been fixed in 0.9.5 and 0.10.5 maintenance releases. ReferencesFixed in https://github.com/quinn-rs/quinn/pull/1667, backported in https://github.com/quinn-rs/quinn/pull/1668 and https://github.com/quinn-rs/quinn/pull/1669. Fixed in
0.9.5
References Updated Sep 10, 2026 · Source: OSV.dev |
0.5.2
unknown
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
0.5.0
unknown
3 CVEs
CVE-2026-25800
GHSA-4w2j-m93h-cj5j
RUSTSEC-2026-0185
Jul 24, 2026
Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassembly
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryThe Fixed in
0.11.15
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-31812
GHSA-6xvm-j4wr-6v98
RUSTSEC-2026-0037
Mar 11, 2026
Quinn affected by unauthenticated remote DoS via panic in QUIC transport parameter parsing
High
Network
Low
None
None
SummaryA remote, unauthenticated attacker can trigger a denial of service in applications using vulnerable DetailsThe issue is panic-on-untrusted-input in QUIC transport parameter parsing.
In Observed output:
PoCReproduces against the upstream Quinn server example.
Observed output
ImpactVulnerability type: Remote Denial of Service (panic/crash)
Attack requirements: Network reachability to UDP QUIC listener
Authentication/privileges: None
Who is impacted: Any server/application using affected This vulnerability was originally submitted by @revofusion to the Ethereum Foundation bug bounty program Fixed in
0.11.14
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-42805
GHSA-q8wc-j5m9-27w3
RUSTSEC-2023-0063
Sep 21, 2023
Denial of Service issue in quinn-proto
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactReceiving unknown QUIC frames in a QUIC packet could result in a panic. PatchesThe problem has been fixed in 0.9.5 and 0.10.5 maintenance releases. ReferencesFixed in https://github.com/quinn-rs/quinn/pull/1667, backported in https://github.com/quinn-rs/quinn/pull/1668 and https://github.com/quinn-rs/quinn/pull/1669. Fixed in
0.9.5
References Updated Sep 10, 2026 · Source: OSV.dev |
0.5.0
unknown
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
0.4.0
unknown
3 CVEs
CVE-2026-25800
GHSA-4w2j-m93h-cj5j
RUSTSEC-2026-0185
Jul 24, 2026
Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassembly
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryThe Fixed in
0.11.15
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-31812
GHSA-6xvm-j4wr-6v98
RUSTSEC-2026-0037
Mar 11, 2026
Quinn affected by unauthenticated remote DoS via panic in QUIC transport parameter parsing
High
Network
Low
None
None
SummaryA remote, unauthenticated attacker can trigger a denial of service in applications using vulnerable DetailsThe issue is panic-on-untrusted-input in QUIC transport parameter parsing.
In Observed output:
PoCReproduces against the upstream Quinn server example.
Observed output
ImpactVulnerability type: Remote Denial of Service (panic/crash)
Attack requirements: Network reachability to UDP QUIC listener
Authentication/privileges: None
Who is impacted: Any server/application using affected This vulnerability was originally submitted by @revofusion to the Ethereum Foundation bug bounty program Fixed in
0.11.14
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-42805
GHSA-q8wc-j5m9-27w3
RUSTSEC-2023-0063
Sep 21, 2023
Denial of Service issue in quinn-proto
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactReceiving unknown QUIC frames in a QUIC packet could result in a panic. PatchesThe problem has been fixed in 0.9.5 and 0.10.5 maintenance releases. ReferencesFixed in https://github.com/quinn-rs/quinn/pull/1667, backported in https://github.com/quinn-rs/quinn/pull/1668 and https://github.com/quinn-rs/quinn/pull/1669. Fixed in
0.9.5
References Updated Sep 10, 2026 · Source: OSV.dev |
0.4.0
unknown
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
0.3.0
unknown
3 CVEs
CVE-2026-25800
GHSA-4w2j-m93h-cj5j
RUSTSEC-2026-0185
Jul 24, 2026
Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassembly
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryThe Fixed in
0.11.15
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-31812
GHSA-6xvm-j4wr-6v98
RUSTSEC-2026-0037
Mar 11, 2026
Quinn affected by unauthenticated remote DoS via panic in QUIC transport parameter parsing
High
Network
Low
None
None
SummaryA remote, unauthenticated attacker can trigger a denial of service in applications using vulnerable DetailsThe issue is panic-on-untrusted-input in QUIC transport parameter parsing.
In Observed output:
PoCReproduces against the upstream Quinn server example.
Observed output
ImpactVulnerability type: Remote Denial of Service (panic/crash)
Attack requirements: Network reachability to UDP QUIC listener
Authentication/privileges: None
Who is impacted: Any server/application using affected This vulnerability was originally submitted by @revofusion to the Ethereum Foundation bug bounty program Fixed in
0.11.14
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-42805
GHSA-q8wc-j5m9-27w3
RUSTSEC-2023-0063
Sep 21, 2023
Denial of Service issue in quinn-proto
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactReceiving unknown QUIC frames in a QUIC packet could result in a panic. PatchesThe problem has been fixed in 0.9.5 and 0.10.5 maintenance releases. ReferencesFixed in https://github.com/quinn-rs/quinn/pull/1667, backported in https://github.com/quinn-rs/quinn/pull/1668 and https://github.com/quinn-rs/quinn/pull/1669. Fixed in
0.9.5
References Updated Sep 10, 2026 · Source: OSV.dev |
0.3.0
unknown
Dependencies (15)
+ 7 more
Changelog
Compare changes
|
|
0.2.0
unknown
3 CVEs
CVE-2026-25800
GHSA-4w2j-m93h-cj5j
RUSTSEC-2026-0185
Jul 24, 2026
Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassembly
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryThe Fixed in
0.11.15
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-31812
GHSA-6xvm-j4wr-6v98
RUSTSEC-2026-0037
Mar 11, 2026
Quinn affected by unauthenticated remote DoS via panic in QUIC transport parameter parsing
High
Network
Low
None
None
SummaryA remote, unauthenticated attacker can trigger a denial of service in applications using vulnerable DetailsThe issue is panic-on-untrusted-input in QUIC transport parameter parsing.
In Observed output:
PoCReproduces against the upstream Quinn server example.
Observed output
ImpactVulnerability type: Remote Denial of Service (panic/crash)
Attack requirements: Network reachability to UDP QUIC listener
Authentication/privileges: None
Who is impacted: Any server/application using affected This vulnerability was originally submitted by @revofusion to the Ethereum Foundation bug bounty program Fixed in
0.11.14
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-42805
GHSA-q8wc-j5m9-27w3
RUSTSEC-2023-0063
Sep 21, 2023
Denial of Service issue in quinn-proto
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactReceiving unknown QUIC frames in a QUIC packet could result in a panic. PatchesThe problem has been fixed in 0.9.5 and 0.10.5 maintenance releases. ReferencesFixed in https://github.com/quinn-rs/quinn/pull/1667, backported in https://github.com/quinn-rs/quinn/pull/1668 and https://github.com/quinn-rs/quinn/pull/1669. Fixed in
0.9.5
References Updated Sep 10, 2026 · Source: OSV.dev |
0.2.0
unknown
Dependencies (15)
+ 7 more
Changelog
Compare changes
|
|
0.1.0
unknown
3 CVEs
CVE-2026-25800
GHSA-4w2j-m93h-cj5j
RUSTSEC-2026-0185
Jul 24, 2026
Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassembly
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryThe Fixed in
0.11.15
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-31812
GHSA-6xvm-j4wr-6v98
RUSTSEC-2026-0037
Mar 11, 2026
Quinn affected by unauthenticated remote DoS via panic in QUIC transport parameter parsing
High
Network
Low
None
None
SummaryA remote, unauthenticated attacker can trigger a denial of service in applications using vulnerable DetailsThe issue is panic-on-untrusted-input in QUIC transport parameter parsing.
In Observed output:
PoCReproduces against the upstream Quinn server example.
Observed output
ImpactVulnerability type: Remote Denial of Service (panic/crash)
Attack requirements: Network reachability to UDP QUIC listener
Authentication/privileges: None
Who is impacted: Any server/application using affected This vulnerability was originally submitted by @revofusion to the Ethereum Foundation bug bounty program Fixed in
0.11.14
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-42805
GHSA-q8wc-j5m9-27w3
RUSTSEC-2023-0063
Sep 21, 2023
Denial of Service issue in quinn-proto
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactReceiving unknown QUIC frames in a QUIC packet could result in a panic. PatchesThe problem has been fixed in 0.9.5 and 0.10.5 maintenance releases. ReferencesFixed in https://github.com/quinn-rs/quinn/pull/1667, backported in https://github.com/quinn-rs/quinn/pull/1668 and https://github.com/quinn-rs/quinn/pull/1669. Fixed in
0.9.5
References Updated Sep 10, 2026 · Source: OSV.dev |
0.1.0
unknown
Dependencies (20)
+ 12 more
Changelog
|