{"id":"CVE-2021-28036","details":"An issue was discovered in the quinn crate before 0.7.0 for Rust. It may have invalid memory access for certain versions of the standard library because it relies on a direct cast of std::net::SocketAddrV4 and std::net::SocketAddrV6 data structures.","aliases":["GHSA-fhv4-fx3v-77w6","RUSTSEC-2021-0035"],"modified":"2026-09-12T08:17:54.942817Z","published":"2021-03-05T09:15:14.380Z","references":[{"type":"FIX","url":"https://rustsec.org/advisories/RUSTSEC-2021-0035.html"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/quinn-rs/quinn","events":[{"introduced":"0"},{"fixed":"061a74fb6ef67b12f78bc2a3cfc9906e54762eeb"},{"introduced":"41bf1db60d9db95913224811280a2dd171b02e13"},{"fixed":"5e54ac6dcdfe9dafff011a56de3d234470761400"}],"database_specific":{"cpe":"cpe:2.3:a:quinn_project:quinn:*:*:*:*:*:rust:*:*","extracted_events":[{"introduced":"0"},{"fixed":"0.5.4"},{"introduced":"0.6.0"},{"fixed":"0.6.2"}],"source":"CPE_RANGE"}}],"versions":["quinn-udp-0.6.1","quinn-udp-0.6.0","quinn-udp-0.5.3","quinn-udp-0.5.2","quinn-proto-0.11.3","quinn-0.11.2","0.11.2","0.11.1","0.11.0","0.9.3","0.10.1","0.10.0","0.9.2","0.9.1","0.9.0","udp-0.2.0","0.8.0","0.7.0","0.6.1","0.6.0","0.5.0","0.4.0","0.3.0","0.2.0","0.1.0","pre-quinn-quicr"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-28036.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}