PT-2026-24465 · Quinn · Quinn

·

CVE-2026-31812

·

Published

2026-03-09

·

Updated

2026-06-01

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Quinn versions prior to 0.11.14
Description A remote, unauthenticated attacker can cause a denial of service in applications using vulnerable Quinn versions by sending a specially crafted QUIC Initial packet containing malformed quic transport parameters. The issue occurs because attacker-controlled variable-length integers (varints) are decoded using unwrap(), and truncated encodings lead to a panic. This is exploitable over the network with a single packet and requires no prior trust or authentication.
Recommendations Update to version 0.11.14 or later.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-31812
GHSA-6XVM-J4WR-6V98
OPENSUSE-SU-2026:10380-1
OPENSUSE-SU-2026:10382-1
OPENSUSE-SU-2026:10383-1
OPENSUSE-SU-2026:10384-1
OPENSUSE-SU-2026:20569-1
OPENSUSE-SU-2026:20865-1
RUSTSEC-2026-0037
SUSE-RU-2026:1001-1
SUSE-SU-2026:1337-1
SUSE-SU-2026:1415-1
SUSE-SU-2026:21357-1
SUSE-SU-2026:22005-1

Affected Products

Quinn