Memory Exhaustion Vulnerability in Quinn QUIC Transport Protocol Implementation
CVE-2026-25800
7.5HIGH
What is CVE-2026-25800?
The Quinn implementation of the IETF QUIC transport protocol has a vulnerability due to inefficient handling of unordered stream fragments in its Assembler component. This oversight affects versions 0.1.0 to 0.11.14, where the system can experience excessive memory utilization, especially when peers send non-contiguous fragments. As a result, the receiving connection faces high buffer overhead, which may lead to memory exhaustion scenarios. The issue is resolved in version 0.11.15.
Affected Version(s)
quinn >= 0.1.0, < 0.11.15
