Skip to content

Fix RUSTSEC-2026-0037: Update quinn-proto to 0.11.14#2770

Merged
CommanderStorm merged 2 commits intomainfrom
copilot/run-rustsec-audit-check
Mar 10, 2026
Merged

Fix RUSTSEC-2026-0037: Update quinn-proto to 0.11.14#2770
CommanderStorm merged 2 commits intomainfrom
copilot/run-rustsec-audit-check

Conversation

Copy link
Contributor

Copilot AI commented Mar 10, 2026

quinn-proto v0.11.13 has a DoS vulnerability (RUSTSEC-2026-0037 / GHSA-6xvm-j4wr-6v98): invalid QUIC transport parameters trigger a panic. Patched in >=0.11.14.

Proposed Change(s)

  • Run cargo update -p quinn-proto to bump quinn-proto 0.11.130.11.14 in Cargo.lock (quinn-proto is a transitive dep via reqwestquinn)

Checklist

  • Documentation
    • No need to update the documentation

💬 We'd love your input! Share your thoughts on Copilot coding agent in our 2 minute survey.

…lity)

Co-authored-by: CommanderStorm <26258709+CommanderStorm@users.noreply.github.com>
Copilot AI changed the title [WIP] Run rustsec/audit-check with specified ignores Fix RUSTSEC-2026-0037: Update quinn-proto to 0.11.14 Mar 10, 2026
@CommanderStorm CommanderStorm marked this pull request as ready for review March 10, 2026 19:49
Copilot AI review requested due to automatic review settings March 10, 2026 19:49
Copy link
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot wasn't able to review any files in this pull request.

@CommanderStorm CommanderStorm enabled auto-merge (squash) March 10, 2026 19:49
@CommanderStorm CommanderStorm merged commit 815f6bd into main Mar 10, 2026
30 checks passed
@CommanderStorm CommanderStorm deleted the copilot/run-rustsec-audit-check branch March 10, 2026 20:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants