What is CVE-2026-25800?
CVE-2026-25800 is a vulnerability in the `Assembler` component of the Quinn QUIC protocol implementation, which incurs overhead when processing non-contiguous stream fragments. It affects versions from 0.1.0 to prior to 0.11.15. Attackers may exploit crafted stream fragments to cause memory or performance issues on affected systems. Users are advised to upgrade to version 0.11.15 or later.
Azərbaycanca: CVE-2026-25800 Quinn QUIC protokol implementasiyasında `Assembler` komponentində intervalı olmayan stream fraqmentlərinin işlənməsi zamanı yaranan zəiflikdir. Bu, 0.1.0-dan 0.11.15-ə qədər versiyalara təsir edir. Təsirə məruz qalan sistemlərdə hücumçu xüsusi hazırlanmış stream fraqmentləri ilə yaddaş və ya performans problemləri yarada bilər. İstifadəçilərə Quinn kitabxanasını 0.11.15 və ya daha yeni versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-400
FAQ2
Which component of Quinn is affected by CVE-2026-25800?
The vulnerability affects the `Assembler` component of the Quinn QUIC protocol implementation.
What is the recommended patched version for CVE-2026-25800?
Users are advised to upgrade Quinn to version 0.11.15 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.