Quinn Project maintains a QUIC protocol implementation library that, despite narrow scope, addresses a foundational transport layer present in modern network stacks and browser implementations. The recurring weakness classes—control flow correctness, input validation, and memory-boundary handling—reflect the low-level protocol parsing and state-machine demands inherent to a standards-based transport codec. Current severity, exploitation activity, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Quinn Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-28036HIGH An issue was discovered in the quinn crate before 0.7.0 for Rust. It may have invalid memory access for certain versions of the standard library because it relies on a direct cast | Mar 5, 2021 | 7.5 | 23 | NO | NO |
CVE-2024-45311HIGH Quinn is a pure-Rust, async-compatible implementation of the IETF QUIC transport protocol. As of quinn-proto 0.11, it is possible for a server to `accept()`, `retry()`, `refuse()`, | Sep 2, 2024 | 7.5 | 22 | NO | NO |
CVE-2023-42805HIGH quinn-proto is a state machine for the QUIC transport protocol. Prior to versions 0.9.5 and 0.10.5, receiving unknown QUIC frames in a QUIC packet could result in a panic. The prob | Sep 21, 2023 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Quinn Project.
Media articles that mention a CVE ID that affects a product developed by Quinn Project — matched by CVE ID, not by vendor name.