quinn-proto is vulnerable to Denial of Service (DoS)
75
High Risk
quinn-proto's outgoing datagram queue keeps a payload_bytes count of buffered data to bound memory use. When a full buffer evicts queued datagrams, both Datagrams::send and the buffer's own eviction logic subtract the evicted size from payload_bytes, so the reduction is counted twice. Sustained eviction drains the counter past its true value, causing an overflow panic in debug builds or a desynchronization panic in release builds inside send_datagram. The fix removes the redundant subtraction at the call site.
You are affected if you are using a version that falls within the vulnerable range and you send datagrams with send_datagram.
quinn-proto is vulnerable to Denial of Service (DoS) in versions 0.11.17 - 0.11.17.
Upgrade the quinn-proto library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.