Skip to content

fix(deps): bump quinn-proto to 0.11.15 (GHSA-4w2j-m93h-cj5j) - #82

Merged
kipavy merged 1 commit into
devfrom
fix/quinn-proto-cve
Jul 29, 2026
Merged

fix(deps): bump quinn-proto to 0.11.15 (GHSA-4w2j-m93h-cj5j)#82
kipavy merged 1 commit into
devfrom
fix/quinn-proto-cve

Conversation

@kipavy

@kipavy kipavy commented Jul 29, 2026

Copy link
Copy Markdown
Contributor

Closes Dependabot alert #29 (high).

quinn-proto < 0.11.15 is vulnerable to remote memory exhaustion via unbounded out-of-order stream reassembly (GHSA-4w2j-m93h-cj5j).

Transitive dependency: reqwest -> quinn -> quinn-proto. Lockfile-only patch bump, no manifest or source changes.

Verified with cargo check --manifest-path src-tauri/Cargo.toml --locked (green, lockfile unchanged by the check).

The three open russh alerts (GHSA-5xvq-cp9x-6p6r, GHSA-g9hv-x236-4qp3, GHSA-cqjc-rmpq-xprq) are already fixed on dev at 0.62.4 and will close once dev reaches main.

Remote memory exhaustion via unbounded out-of-order stream reassembly.
Transitive via reqwest -> quinn.
@kipavy
kipavy merged commit b2ef74d into dev Jul 29, 2026
2 checks passed
@kipavy
kipavy deleted the fix/quinn-proto-cve branch July 29, 2026 14:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant