PT-2026-64151 · Quinn · Quinn

CVE-2026-25800

·

Published

2026-06-22

·

Updated

2026-07-24

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Quinn versions 0.1.0 through 0.11.14
Description The Assembler component, which organizes unordered stream fragments into consecutive chunks, incurs significant overhead when processing non-contiguous fragments. When a reader accesses a RecvStream in order, the system becomes sensitive to peers that send fragments with numerous gaps, as these cannot be defragmented. This behavior leads to high buffer overhead on the receiving connection, which can result in memory exhaustion.
Recommendations Update to version 0.11.15.

Exploit

Fix

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-25800
GHSA-4W2J-M93H-CJ5J
RUSTSEC-2026-0185

Affected Products

Quinn