CVE-2026-31812: CWE-248: Uncaught Exception in quinn-rs quinn
Quinn is a pure-Rust, async-compatible implementation of the IETF QUIC transport protocol. Prior to 0.11.14, a remote, unauthenticated attacker can trigger a denial of service in applications using vulnerable quinn versions by sending a crafted QUIC Initial packet containing malformed quic_transport_parameters. In quinn-proto parsing logic, attacker-controlled varints are decoded with unwrap(), so truncated encodings cause Err(UnexpectedEnd) and panic. This is reachable over the network with a single packet and no prior trust or authentication. This vulnerability is fixed in 0.11.14.
AI Analysis
Technical Summary
Quinn versions before 0.11.14 contain a vulnerability where attacker-controlled varints in QUIC Initial packets are decoded using unwrap(), leading to a panic on truncated encodings (Err(UnexpectedEnd)). This uncaught exception can be triggered remotely without authentication by sending a single crafted packet, causing denial of service in applications using vulnerable quinn versions. The issue is tracked as CWE-248 (Uncaught Exception) and is fixed in version 0.11.14.
Potential Impact
The vulnerability allows a remote, unauthenticated attacker to cause a denial of service by crashing or restarting applications using vulnerable quinn versions. The impact is limited to application availability; host system availability is not at risk. There is no impact on confidentiality or integrity. No known exploits in the wild have been reported.
Mitigation Recommendations
A fix is available in quinn version 0.11.14. Users should upgrade to version 0.11.14 or later to remediate this vulnerability. Red Hat advisories indicate that no effective mitigations other than upgrading are available that meet their criteria. Therefore, upgrading is the recommended remediation.
CVE-2026-31812: CWE-248: Uncaught Exception in quinn-rs quinn
Description
Quinn is a pure-Rust, async-compatible implementation of the IETF QUIC transport protocol. Prior to 0.11.14, a remote, unauthenticated attacker can trigger a denial of service in applications using vulnerable quinn versions by sending a crafted QUIC Initial packet containing malformed quic_transport_parameters. In quinn-proto parsing logic, attacker-controlled varints are decoded with unwrap(), so truncated encodings cause Err(UnexpectedEnd) and panic. This is reachable over the network with a single packet and no prior trust or authentication. This vulnerability is fixed in 0.11.14.
CVSS v4.0
Score 8.7high
Affected software
quinn-rs
quinn
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Quinn versions before 0.11.14 contain a vulnerability where attacker-controlled varints in QUIC Initial packets are decoded using unwrap(), leading to a panic on truncated encodings (Err(UnexpectedEnd)). This uncaught exception can be triggered remotely without authentication by sending a single crafted packet, causing denial of service in applications using vulnerable quinn versions. The issue is tracked as CWE-248 (Uncaught Exception) and is fixed in version 0.11.14.
Potential Impact
The vulnerability allows a remote, unauthenticated attacker to cause a denial of service by crashing or restarting applications using vulnerable quinn versions. The impact is limited to application availability; host system availability is not at risk. There is no impact on confidentiality or integrity. No known exploits in the wild have been reported.
Mitigation Recommendations
A fix is available in quinn version 0.11.14. Users should upgrade to version 0.11.14 or later to remediate this vulnerability. Red Hat advisories indicate that no effective mitigations other than upgrading are available that meet their criteria. Therefore, upgrading is the recommended remediation.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-03-09T16:33:42.914Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-31812","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:22862","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:13545","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:19712","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:5459","vendor":"Red Hat"}]
Threat ID: 69b08d502f860ef943c51492
Added to database: 03/10/2026, 21:29:52 UTC
Last enriched: 08/13/2026, 14:04:15 UTC
Last updated: 09/13/2026, 22:01:33 UTC
Views: 221
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.