PT-2026-24465 · Quinn · Quinn

·

CVE-2026-31812

·

Published

2026-03-09

·

Updated

2026-08-25

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions quinn versions prior to 0.11.14
Description A remote, unauthenticated attacker can trigger a denial of service in applications using the quinn-proto QUIC transport protocol implementation. The issue occurs when a crafted QUIC Initial packet containing malformed quic transport parameters is sent to the application. Within the parsing logic of quinn-proto, attacker-controlled varints (variable-length integers) are decoded using the unwrap() function. If the encodings are truncated, it results in an Err(UnexpectedEnd) and causes the application to panic and crash. This can be achieved over the network with a single packet without requiring prior trust or authentication.
Recommendations Update to version 0.11.14.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-31812
GHSA-6XVM-J4WR-6V98
OPENSUSE-SU-2026:10380-1
OPENSUSE-SU-2026:10382-1
OPENSUSE-SU-2026:10383-1
OPENSUSE-SU-2026:10384-1
OPENSUSE-SU-2026:20569-1
OPENSUSE-SU-2026:20865-1
RUSTSEC-2026-0037
SUSE-RU-2026:1001-1
SUSE-SU-2026:1337-1
SUSE-SU-2026:1415-1
SUSE-SU-2026:21357-1
SUSE-SU-2026:22005-1

Affected Products

Quinn