---
id: CVE-2026-25800
title: >-
  quinn: Quinn: Remote memory exhaustion via malformed QUIC stream fragments
  (CVE-2026-25800)
summary: >-
  A flaw was found in Quinn, a Rust implementation of the QUIC transport
  protocol. A remote attacker can exploit this vulnerability by sending
  specially crafted QUIC stream fragments with many gaps. This can lead to high
  buffer overhead in t…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cvssSource: vendor
cwe: CWE-770
vendor: Red Hat
product: quinn-proto
affected:
  - 'quinn-proto >= 0.1.0, < 0.11.15'
patched:
  - quinn-proto 0.11.15
published: '2026-07-23'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T04:09:33+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-25800.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-25800.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-25800'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2506588'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-25800'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-25800'
  - url: 'https://github.com/quinn-rs/quinn/pull/2694'
  - url: 'https://github.com/quinn-rs/quinn/security/advisories/GHSA-4w2j-m93h-cj5j'
  - url: 'https://rustsec.org/advisories/RUSTSEC-2026-0185.html'
  - url: >-
      https://github.com/quinn-rs/quinn/commit/fed0321a9a672819662caab37f5662f1ad91308e
  - url: 'https://github.com/quinn-rs/quinn'
  - url: 'https://github.com/quinn-rs/quinn/releases/tag/quinn-proto-0.11.15'
tags:
  - csaf
  - vex
  - red-hat
  - osv
  - rust
epss: 0.00609
epssPercentile: 0.46835
aliases:
  - GHSA-4w2j-m93h-cj5j
  - RUSTSEC-2026-0185
ecosystem: rust
ingestedAt: '2026-07-24T19:07:03.673Z'
---

## Overview

A flaw was found in Quinn, a Rust implementation of the QUIC transport protocol. A remote attacker can exploit this vulnerability by sending specially crafted QUIC stream fragments with many gaps. This can lead to high buffer overhead in the Assembler component, causing memory exhaustion and a denial of service (DoS) for the receiving connection.

## Vendor advisories

- **Red Hat VEX** · Important · updated 2026-09-25 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-25800.json)

**quinn: Quinn: Remote memory exhaustion via malformed QUIC stream fragments** — rated Important by Red Hat. Released 2026-07-23, updated 2026-09-25.

Not affected:

- Ansible Automation Orchestrator 2026
- Confidential Compute Attestation
- Logging Subsystem for Red Hat OpenShift
- OpenShift Lightspeed
- Red Hat Ansible Automation Platform 2
- Red Hat Enterprise Linux 10
- Red Hat Enterprise Linux 7
- Red Hat Enterprise Linux 8
- Red Hat Enterprise Linux 9
- Red Hat Enterprise Linux AI (RHEL AI) 3

## Remediation

Refer to the advisory for fix availability.

## Package advisory (CVE-2026-25800)

Affected packages:

- `quinn-proto >= 0.1.0, < 0.11.15`

Patched in:

- `quinn-proto 0.11.15`

Source: https://osv.dev/vulnerability/GHSA-4w2j-m93h-cj5j
