{"id":"CVE-2026-31812","aliases":["GHSA-6xvm-j4wr-6v98","RUSTSEC-2026-0037"],"url":"https://o3.security/vulnerability/CVE-2026-31812","summary":"Quinn affected by unauthenticated remote DoS via panic in QUIC transport parameter parsing","details":"Quinn is a pure-Rust, async-compatible implementation of the IETF QUIC transport protocol. Prior to 0.11.14, a remote, unauthenticated attacker can trigger a denial of service in applications using vulnerable quinn versions by sending a crafted QUIC Initial packet containing malformed quic_transport_parameters. In quinn-proto parsing logic, attacker-controlled varints are decoded with unwrap(), so truncated encodings cause Err(UnexpectedEnd) and panic. This is reachable over the network with a single packet and no prior trust or authentication. This vulnerability is fixed in 0.11.14.","published":"2026-03-10T21:04:36.812Z","modified":"2026-08-27T11:31:12.754596433Z","cvss":null,"epss":{"score":0.005,"percentile":0.40531,"asOf":"2026-08-24"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"crates.io","name":"quinn-proto","fixedVersion":"0.11.14"}],"fix":null,"references":[{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-31812.json"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:13545"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:19712"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:22862"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:5459"},{"type":"ADVISORY","url":"https://access.redhat.com/security/cve/CVE-2026-31812"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/31xxx/CVE-2026-31812.json"},{"type":"ADVISORY","url":"https://github.com/quinn-rs/quinn/security/advisories/GHSA-6xvm-j4wr-6v98"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-31812"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2446330"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-27T11:31:12.754596433Z"}}