CVE-2026-31812Patch

LOWCVSS 8.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Quinn is a pure-Rust, async-compatible implementation of the IETF QUIC transport protocol. Prior to 0.11.14, a remote, unauthenticated attacker can trigger a denial of service in applications using vulnerable quinn versions by sending a crafted QUIC Initial packet containing malformed quic_transport_parameters. In quinn-proto parsing logic, attacker-controlled varints are decoded with unwrap(), so truncated encodings cause Err(UnexpectedEnd) and panic. This is reachable over the network with a single packet and no prior trust or authentication. This vulnerability is fixed in 0.11.14.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-248

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 4 signals
  • Peaked 1d ago at 2 mentions (2026-03-20); latest day: 1
  • 4 total mentions across 3 days

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-03-10: 1Mentions · 2026-03-20: 2Mentions · 2026-05-11: 1Patch / Workaround · 2026-03-10: 1Patch / Workaround · 2026-03-20: 2Patch / Workaround · 2026-05-11: 1Technical Details · 2026-03-10: 1Technical Details · 2026-03-20: 2Technical Details · 2026-05-11: 103-1003-2005-11
Signal classification1 categories
Patch
4100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-101
Patch1
2026-03-202
Patch2
2026-05-111
Patch1
Full discourse4 posts
  • Ferron ⚡🦀@ferron_web
    Patch

    Ferron 1.3.10 is here! 🥳 - CVE-2026-31812 (QUIC DoS in quinn-proto) fix

    Post summary

    Ferron 1.3.10 includes a fix for CVE‑2026‑31812, a QUIC denial‑of‑service flaw in quinn‑proto. No exploitation or PoC details are provided.

    11080508
    1.5K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    Critical security advisory for #Fedora 43 users: The bpfman package has been updated to fix CVE-2026-31812, a high-impact Denial of Service vulnerability in the quinn-proto QUIC implementation. Read more: 👉 https://tinyurl.com/3np7ekau #Security https://t.co/GyzeNW8ztk

    Post summary

    Fedora 43 users are advised to update the bpfman package to address CVE‑2026‑31812, a high‑impact DoS flaw in the quinn‑proto QUIC implementation.

    0000087
    1.5K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    Critical security advisory for #Fedora 43 users: The bpfman package has been updated to fix CVE-2026-31812, a high-impact Denial of Service vulnerability in the quinn-proto QUIC implementation. Read more: 👉 https://tinyurl.com/4wdprtnd #Security https://t.co/EETgBoJTmY

    Post summary

    The advisory announces that Fedora 43’s bpfman package has been updated to patch CVE‑2026‑31812, a high‑impact Denial of Service vulnerability in the quinn‑proto QUIC implementation, with no PoC or active exploitation mentioned.

    0000091
    1.5K followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-31812 Quinn is a pure-Rust, async-compatible implementation of the IETF QUIC transport protocol. Prior to 0.11.14, a remote, unauthenticated attacker can trigger a denial o… https://www.cve.org/CVERecord?id=CVE-2026-31812

    Post summary

    The post notes that before version 0.11.14 of Quinn, an attacker could cause a denial of service, and that upgrading to 0.11.14 resolves this issue.

    00000154
    56.7K followersView on X

Explore more