s2n-quic Rust Implementation Vulnerable to Excessive Memory Allocation
- Severity
- HIGH
- Affected component
- s2n-quic (cargo)
- Affected versions
- < 1.31.0 or < 1.82.0 or >= 1.22.0, < 1.23.0 or >= 1.22.0, <= 1.22.0 or < 1.25.0
- Patched version
- v1.82.0
An early warning has been issued for a vulnerability in the s2n-quic Rust implementation of the QUIC protocol. Versions <= v1.81.0 are reportedly affected.
What happened
The s2n-quic Rust implementation of the QUIC protocol is under investigation for a vulnerability that allows excessive memory allocation. This vulnerability could enable an unauthenticated user to cause a denial of service by sending specially crafted CRYPTO frames. Versions <= v1.81.0 appear to be vulnerable. The issue was first flagged on 2026-08-14T21:44:19+00:00. There is no evidence that this vulnerability has been exploited in the wild.
Affected versions include s2n-quic (cargo) < 1.31.0 or < 1.82.0 or >= 1.22.0, < 1.23.0 or >= 1.22.0, <= 1.22.0 or < 1.25.0. The patched version is v1.82.0. Users of these versions should assess their exposure and take appropriate action to mitigate the risk.
What to do about it
- Upgrade to s2n-quic version v1.82.0 to mitigate the vulnerability.
- Check your dependencies for any versions of s2n-quic that fall within the affected ranges.
- If you are using an affected version, plan and execute an upgrade to the patched version as soon as possible.
- Monitor the primary sources for updates on the vulnerability and any additional patches that may be released.
How 0Day would have caught this
s2n-quic is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
You are affected if you are using s2n-quic (cargo) < 1.31.0 or < 1.82.0 or >= 1.22.0, < 1.23.0 or >= 1.22.0, <= 1.22.0 or < 1.25.0.
What should I do right now?
Upgrade to s2n-quic version v1.82.0 to mitigate the vulnerability.
Is there an official fix available?
Yes, the patched version is v1.82.0.