NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
crates.io · #362 most downloaded on crates.io
State machine for the QUIC transport protocol
Last release 8 days ago
30 Sep 2026
Release timing varies
gaps range from 2 weeks to 6 months
Rarely documented
notes for 8 of 49 stable releases
2 versions withdrawn
withdrawn after publishing
8 years old
51 releases · first in 2018
MAX_STREAM_DATA frame opens streams over the stream limit
Fixes several advisories:
blocked_readers by @robertkiel in #2880One column per quarter.
Three more security issues were reported and fixed since 0.11.17:
Three more security issues were reported and fixed since 0.11.17:
Datagrams::send() double-subtracts payload_bytes on the drop-oldest path, panicking the senderThis release fixes three remote memory exhaustion issues. See GHSA-qfwj-vfxf-92j2 , GHSA-2hv7-gw8g-gpq5 , and GHSA-hmxj-32vh-65vr for more details, an
This release fixes three remote memory exhaustion issues. See GHSA-qfwj-vfxf-92j2, GHSA-2hv7-gw8g-gpq5, and GHSA-hmxj-32vh-65vr for more details, and #2789 for the fixes.
Full Changelog: quinn-proto-0.11.16...quinn-proto-0.11.17
0.11.x: upgrade dependencies by @djc in #2707
This release fixes a remote memory exhaustion issue in the quinn-proto Assembler . See GHSA-4w2j-m93h-cj5j for more details and #2694 for the fix.
This release fixes a remote memory exhaustion issue in the quinn-proto Assembler. See GHSA-4w2j-m93h-cj5j for more details and #2694 for the fix.
Two sponsoring organizations participated in coordinated disclosure. If this is relevant to your organization, please contact us to keep support Quinn maintenance.
@jxs reported a denial of service issue in quinn-proto 5 days ago:
@jxs reported a denial of service issue in quinn-proto 5 days ago:
We coordinated with them to release this version to patch the issue. Unfortunately the maintainers missed these issues during code review and we did not have enough fuzzing coverage -- we regret the oversight and have added an additional fuzzing target.
Organizations that want to participate in coordinated disclosure can contact us privately to discuss terms.
quinn: Remove explicit write future structs by @gretchenfrage in #2226
SendStream::stopped static by @Frando in #2220Connection::side() in quinn by @abonander in #2261async_io::UdpSocket when unused by @matheus23 in #2264Connection::set_send_window() by @abonander in #2268Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
fix: reuse existing socket for probing GRO/GSO support by @thomaseizinger in #2565
retry_if_interrupted helper by @larseggert in #2583sendmsg_x/recvmsg_x via dlsym by @larseggert in #2571Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →