Skip to content

[Vanta] Remediate quinn-proto to 0.11.14 (CIP-2900)#115

Merged
tobyhede merged 1 commit intomainfrom
toby/cip-2900-remediate-quinn-proto
Mar 16, 2026
Merged

[Vanta] Remediate quinn-proto to 0.11.14 (CIP-2900)#115
tobyhede merged 1 commit intomainfrom
toby/cip-2900-remediate-quinn-proto

Conversation

@tobyhede
Copy link
Copy Markdown
Contributor

Summary

  • Bumps quinn-proto from 0.11.9 to 0.11.14

CVE-2026-31812

Remote DoS via panic on malformed QUIC Initial packet containing malformed quic_transport_parameters.

References

Test plan

  • CI passes

Fixes CVE-2026-31812: remote DoS via panic on malformed QUIC transport
parameters.

Resolves CIP-2900.
@freshtonic freshtonic self-requested a review March 16, 2026 04:16
@tobyhede tobyhede merged commit 59c9557 into main Mar 16, 2026
3 checks passed
@tobyhede tobyhede deleted the toby/cip-2900-remediate-quinn-proto branch March 16, 2026 04:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants