Security: quinn-rs/quinn
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Zero-length DATAGRAM frames bypass `datagram_receive_buffer_size` (quinn-proto)GHSA-2hv7-gw8g-gpq5 published
Aug 17, 2026 by RalithHigh -
quinn-proto: unbounded pending.retire_cids growth via already-retired NEW_CONNECTION_ID frames (remote memory-exhaustion DoS)GHSA-hmxj-32vh-65vr published
Aug 17, 2026 by RalithModerate -
Stream reassembly memory-exhaustion guard (fix for GHSA-4w2j-m93h-cj5j) can be bypassedGHSA-qfwj-vfxf-92j2 published
Aug 17, 2026 by RalithHigh -
Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassemblyGHSA-4w2j-m93h-cj5j published
Jun 22, 2026 by djcHigh -
Unauthenticated remote DoS via panic in QUIC transport parameter parsing (UnexpectedEnd on malformed varint)GHSA-6xvm-j4wr-6v98 published
Mar 9, 2026 by djcHigh -
Denial of service in quinn-proto when using `Endpoint::retry()`GHSA-vr26-jcq5-fjj8 published
Sep 2, 2024 by djcHigh -
Denial of Service issue in quinn-protoGHSA-q8wc-j5m9-27w3 published
Sep 21, 2023 by djcHigh