s2n-quic vulnerabilities
CVEs whose affected-version data names the s2n-quic package (rust). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-94450High· 7.5Improper validation of the Destination Connection ID length in s2n-quic 1.88.0 and earlier may allow an unauthenticated remote user to cause a denial of service by shutting down a server endpoint via a single crafted UDP datagram
Improper validation of the Destination Connection ID length in s2n-quic 1.88.0 and earlier may allow an unauthenticated remote user to cause a denial of service by shutting down a server endpoint via a single crafted UDP datagram. Only s…
▾ TwilightAWS · s2n-quicvia NVD
CVE-2026-10740Medium· 5.3s2n-quic has excessive memory allocation
s2n-quic has excessive memory allocation
▾ Sunlits2n-quic · s2n-quicEPSS 0.29%via GHSA