highCVSS 7.5Vulnerability
GHSA-4w2j-m93h-cj5j
## Summary The `Assembler` component that assembles unordered stream fragments into consecutive chunks of the stream incurs some overhead for non-contiguous fragments. Readers that read from a `RecvStream` in order (through an `AsyncRead` impl for example) will be sensitive to peers that send fragments while leaving out early parts of the stream, and in particular, fragments with many gaps (because these cannot be defragmented). In such a scenario, the receiving connection suffers from high buffer overhead, enabling memory exhaustion.
Properties
- ghsa_id
- GHSA-4w2j-m93h-cj5j
- summary
- Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassembly
- severity
- high
- cvss_score
- 7.5
- cve_id
- GHSA-4w2j-m93h-cj5j
- cvss_vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- is_ghsa_only
- true
- ghsa_published
- 2026-07-24T14:07:54Z
- source_url
- https://github.com/advisories/GHSA-4w2j-m93h-cj5j
- ghsa_updated
- 2026-07-24T14:07:54Z
Related Entities (4)
HAS_WEAKNESS (1)
→[Weakness]Allocation of Resources Without Limits or Throttling
REPORTED_BY (1)
→[Source]GitHub Advisory Database
VULNERABLE_TO (1)
←[Software]rust/quinn-proto
AFFECTS (1)
→[Software]rust/quinn-proto
Explore deeper with Ninja Signal's threat intelligence graph