ITADN

RUSTSEC-2026-0037: Denial of service in Quinn endpoints

#414Opengithub-actions[bot] 创建于 2026-03-10
| Details | | | --- | --- | | Package | `quinn-proto` | | Version | `0.11.13` | | URL | https://github.com/quinn-rs/quinn/pull/2559 | | Patched Versions | >=0.11.14 | | Unaffected Versions | <0.5.0 | | Aliases | [GHSA-6xvm-j4wr-6v98](https://github.com/advisories/GHSA-6xvm-j4wr-6v98) | Receiving QUIC transport parameters containing invalid values could lead to a panic. Unfortunately the maintainers did not properly assess usage of `unwrap()` calls in the transport parameters parsing code, and we did not have sufficient fuzzing coverage to find this issue. We have since added a fuzzing target to cover this code path.
0 条评论