From 0120eb84d64400f0d21c8447f338db393f487cd0 Mon Sep 17 00:00:00 2001 From: Jordan Gonzalez <30836115+duncanista@users.noreply.github.com> Date: Mon, 22 Jun 2026 16:38:45 -0400 Subject: [PATCH] chore(deps): bump quinn-proto to 0.11.15 (RUSTSEC-2026-0185) Fixes high-severity remote memory exhaustion advisory in quinn-proto from unbounded out-of-order stream reassembly. Pulled in transitively via reqwest -> quinn -> quinn-proto. --- Cargo.lock | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/Cargo.lock b/Cargo.lock index 2646947..991ff1b 100644 --- a/Cargo.lock +++ b/Cargo.lock @@ -2417,9 +2417,9 @@ dependencies = [ [[package]] name = "quinn-proto" -version = "0.11.14" +version = "0.11.15" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "434b42fec591c96ef50e21e886936e66d3cc3f737104fdb9b737c40ffb94c098" +checksum = "4fcb935c5bec503c2f0e306bdd3e58bb9029dcb14fa8d9ac76e3a5256ac0763e" dependencies = [ "bytes", "getrandom 0.3.4",