Memory Exhaustion Vulnerability in Quinn QUIC Transport Protocol Implementation
CVE-2026-25800

7.5HIGH

Key Information:

Vendor

Quinn-rs

Status
Vendor
CVE Published:
23 July 2026

What is CVE-2026-25800?

The Quinn implementation of the IETF QUIC transport protocol has a vulnerability due to inefficient handling of unordered stream fragments in its Assembler component. This oversight affects versions 0.1.0 to 0.11.14, where the system can experience excessive memory utilization, especially when peers send non-contiguous fragments. As a result, the receiving connection faces high buffer overhead, which may lead to memory exhaustion scenarios. The issue is resolved in version 0.11.15.

Affected Version(s)

quinn >= 0.1.0, < 0.11.15

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.