quinn-proto is vulnerable to Denial of Service (DoS)
53
Medium Risk
quinn-proto queues connection ID retirements along two code paths, but only the primary path enforces the cap on pending retirements while the path that handles already retired sequence numbers pushes entries with no cap and no de-duplication. A connected peer can advance the retirement window with a large sequence number and then flood duplicate retired NEW_CONNECTION_ID sequences while withholding acknowledgements, growing the pending queue. This lets a remote peer exhaust memory on the receiver. The fix bounds and de-duplicates the second retirement path.
You are affected if you are using a version that falls within the vulnerable range.
quinn-proto is vulnerable to Denial of Service (DoS) in versions 0.0.1 - 0.11.16.
Upgrade the quinn-proto library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant