Use After Free Affecting quiche package, versions >=0.20.0 <0.29.2


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.17% (7th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-RUST-QUICHE-17660670
  • published27 Jun 2026
  • disclosed19 Jun 2026
  • creditLPardue

Introduced: 19 Jun 2026

NewCVE-2026-11941  (opens in a new tab)
CWE-416  (opens in a new tab)

How to fix?

Upgrade quiche to version 0.29.2 or higher.

Overview

Affected versions of this package are vulnerable to Use After Free in the quiche_connection_id_iter_next and quiche_conn_retired_scid_next functions. An attacker can cause undefined behavior, including process crashes or limited information disclosure, by invoking these FFI functions and dereferencing freed memory. This is only exploitable if the FFI API is enabled at build time.

References

CVSS Base Scores

version 4.0
version 3.1