CVE-2026-31812: Quinn-RS Quinn
Medium severity, CVSS 5.3. EPSS: 0.9% chance of exploitation in the next 30 days.
Quinn is a pure-Rust, async-compatible implementation of the IETF QUIC transport protocol. Prior to 0.11.14, a remote, unauthenticated attacker can trigger a denial of service in applications using vulnerable quinn versions by sending a crafted QUIC Initial packet containing malformed quic_transport_parameters. In quinn-proto parsing logic, attacker-controlled varints are decoded with unwrap(), so truncated encodings cause Err(UnexpectedEnd) and panic. This is reachable over the network with a single packet and no prior trust or authentication. This vulnerability is fixed in 0.11.14.
Affected products
- Quinn-RS Quinn: before 0.11.14 (fixed in 0.11.14)
- Red Hat Confidential Compute Attestation
- Red Hat Logging Subsystem For Red Hat Openshift
- Red Hat Logging Subsystem For Red Hat Openshift 6.4: before 1780052069 (fixed in 1780052069)
- Red Hat Red Hat Ansible Automation Platform 2.6: before 1777398576 (fixed in 1777398576)
- Red Hat Red Hat Enterprise Linux 10
- Red Hat Red Hat Enterprise Linux 7
- Red Hat Red Hat Enterprise Linux 8
- Red Hat Red Hat Enterprise Linux 9
- Red Hat Red Hat Enterprise Linux Ai Rhel Ai 3
- Red Hat Red Hat Openshift Ai 3.3: before 1778596806 (fixed in 1778596806)
- Red Hat Red Hat Openshift Ai Rhoai
- Red Hat Red Hat Openshift Container Platform 4
- Red Hat Red Hat Openshift Update Service
- Red Hat Red Hat Trusted Artifact Signer 1.3: before 1773307309 (fixed in 1773307309)
- Red Hat Red Hat Trusted Profile Analyzer
Published 2026-03-10. Last modified 2026-08-25.