Skip to content

fix(deps): bump quinn-proto to 0.11.15 (RUSTSEC-2026-0185)#1030

Merged
joshrotenberg merged 1 commit into
mainfrom
fix/quinn-proto-rustsec-2026-0185
Jun 25, 2026
Merged

fix(deps): bump quinn-proto to 0.11.15 (RUSTSEC-2026-0185)#1030
joshrotenberg merged 1 commit into
mainfrom
fix/quinn-proto-rustsec-2026-0185

Conversation

@joshrotenberg

Copy link
Copy Markdown
Collaborator

Clears the Security Audit failure now blocking the 0.11.2 release (#1024).

  • RUSTSEC-2026-0185 — remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassembly (DoS). Newly published advisory.
  • Fixed in quinn-proto 0.11.15; this is a lock-only transitive bump (0.11.14 → 0.11.15).
  • cargo audit clean locally after the bump (0 matches for RUSTSEC-2026-0185).

Real vuln with a published patch one version away, so bumping (not ignoring). Once merged, release-plz refreshes #1024 off the patched lock and its Security Audit goes green.

RUSTSEC-2026-0185: remote memory exhaustion in quinn-proto from unbounded
out-of-order stream reassembly (DoS). Newly published; fixed in 0.11.15.
Lock-only transitive bump; cargo audit clean after the update.
@jit-ci

jit-ci Bot commented Jun 25, 2026

Copy link
Copy Markdown

🛡️ Jit Security Scan Results

CRITICAL HIGH MEDIUM

✅ No security findings were detected in this PR


Security scan by Jit

@joshrotenberg
joshrotenberg merged commit be68275 into main Jun 25, 2026
20 checks passed
@joshrotenberg
joshrotenberg deleted the fix/quinn-proto-rustsec-2026-0185 branch June 25, 2026 18:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant