github quinn-rs/quinn quinn-proto-0.11.14
quinn-proto 0.11.14

13 hours ago

@jxs reported a denial of service issue in quinn-proto 5 days ago:

We coordinated with them to release this version to patch the issue. Unfortunately the maintainers missed these issues during code review and we did not have enough fuzzing coverage -- we regret the oversight and have added an additional fuzzing target.

Organizations that want to participate in coordinated disclosure can contact us privately to discuss terms.

What's Changed

  • Fix over-permissive proto dependency edge by @Ralith in #2385
  • 0.11.x: avoid unwrapping VarInt decoding during parameter parsing by @djc in #2559

Don't miss a new quinn release

NewReleases is sending notifications on new releases.