CVE-2026-31812: Quinn-RS Quinn

Medium severity, CVSS 5.3. EPSS: 0.9% chance of exploitation in the next 30 days.

Quinn is a pure-Rust, async-compatible implementation of the IETF QUIC transport protocol. Prior to 0.11.14, a remote, unauthenticated attacker can trigger a denial of service in applications using vulnerable quinn versions by sending a crafted QUIC Initial packet containing malformed quic_transport_parameters. In quinn-proto parsing logic, attacker-controlled varints are decoded with unwrap(), so truncated encodings cause Err(UnexpectedEnd) and panic. This is reachable over the network with a single packet and no prior trust or authentication. This vulnerability is fixed in 0.11.14.

Affected products

  • Quinn-RS Quinn: before 0.11.14 (fixed in 0.11.14)
  • Red Hat Confidential Compute Attestation
  • Red Hat Logging Subsystem For Red Hat Openshift
  • Red Hat Logging Subsystem For Red Hat Openshift 6.4: before 1780052069 (fixed in 1780052069)
  • Red Hat Red Hat Ansible Automation Platform 2.6: before 1777398576 (fixed in 1777398576)
  • Red Hat Red Hat Enterprise Linux 10
  • Red Hat Red Hat Enterprise Linux 7
  • Red Hat Red Hat Enterprise Linux 8
  • Red Hat Red Hat Enterprise Linux 9
  • Red Hat Red Hat Enterprise Linux Ai Rhel Ai 3
  • Red Hat Red Hat Openshift Ai 3.3: before 1778596806 (fixed in 1778596806)
  • Red Hat Red Hat Openshift Ai Rhoai
  • Red Hat Red Hat Openshift Container Platform 4
  • Red Hat Red Hat Openshift Update Service
  • Red Hat Red Hat Trusted Artifact Signer 1.3: before 1773307309 (fixed in 1773307309)
  • Red Hat Red Hat Trusted Profile Analyzer

Published 2026-03-10. Last modified 2026-08-25.