quinn-proto is vulnerable to Denial of Service (DoS)
75
High Risk
quinn-proto reassembles out-of-order STREAM data in a buffer guarded by a chunk cap that is enforced during defragmentation. The defragmentation check only runs when allocation exceeds a dynamic threshold, so a peer that keeps the overhead below that threshold avoids defragmentation and bypasses the chunk limit entirely. A remote, unauthenticated peer can send many small gapped stream fragments to pin more receiver memory than the accounted stream data, leading to memory exhaustion. The fix tightens the reassembly accounting so the guard cannot be bypassed by low overhead fragments.
You are affected if you are using a version that falls within the vulnerable range.
quinn-proto is vulnerable to Denial of Service (DoS) in versions 0.11.15 - 0.11.16.
Upgrade the quinn-proto library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant