Skip to content

[Aikido] Fix 11 security issues in quinn-proto, quick-xml, tauri-plugin-updater and 2 more - #57

Merged
cst8t merged 1 commit into
v0.12.1-developfrom
fix/aikido-security-update-packages-133378994-8nr4
Oct 4, 2026
Merged

cst8t merged 1 commit into
v0.12.1-developfrom
fix/aikido-security-update-packages-133378994-8nr4

Conversation

@aikido-autofix

@aikido-autofix aikido-autofix Bot commented Oct 4, 2026

Copy link
Copy Markdown
Contributor

Upgrade dependencies to fix critical DoS vulnerabilities in quinn-proto (counter overflow, panic on ACK delay) and quick-xml (quadratic XML parsing, stack exhaustion, panic on DOCTYPE).

✅ 11 CVEs resolved by this upgrade

This PR will resolve the following CVEs:

Issue Severity           Description
AIKIDO-2026-562254
HIGH
[quinn-proto] A double-subtraction bug in the outgoing datagram queue's payload byte counter causes it to underflow during sustained eviction, triggering an overflow panic in debug builds or desynchronization panic in release builds, resulting in denial of service.
AIKIDO-2026-560280
HIGH
[quinn-proto] A panic vulnerability occurs when a peer advertises a min_ack_delay transport parameter exceeding the computed maximum ACK delay, causing the clamping operation to fail. This enables a denial of service attack through malformed transport parameters.
AIKIDO-2026-371823
HIGH
[quick-xml] XML parsing with many attributes causes quadratic CPU consumption due to inefficient duplicate detection, enabling denial-of-service attacks that can freeze parsing threads for extended periods without crashing the application.
AIKIDO-2026-173392
MEDIUM
[quick-xml] Unbounded nesting depth in XML parsing causes stack exhaustion (DoS) via deeply nested elements, while malformed inputs can trigger out-of-bounds buffer reads in attribute iteration. The vulnerability affects both the pull reader and serde deserializer when processing untrusted XML.
AIKIDO-2026-356729
LOW
[quick-xml] A DOCTYPE declaration between text runs in XML content causes the deserializer to emit multiple text events instead of merging them, triggering a panic that allows attackers to cause denial of service through crafted XML input.
AIKIDO-2026-176217
LOW
[quick-xml] XML namespace declarations on start tags can trigger unbounded heap allocation with no consumer-imposed limits, allowing untrusted input to exhaust memory and crash the process. The vulnerability is fixed by capping namespace declarations per element at a configurable limit and returning an error when exceeded.
AIKIDO-2026-115347
MEDIUM
[tauri-plugin-updater] A Cross-Site Scripting vulnerability allows frontend code to invoke the updater's check command with allowDowngrades=true, disabling anti-rollback protection and enabling downgrade attacks to previously patched versions. The fix restricts allowDowngrades to Rust-level configuration, preventing WebView code from controlling this security-critical setting.
AIKIDO-2026-122106
MEDIUM
[gix-packetline] A malicious remote can send a specially crafted side-band packet line with an empty payload to trigger an integer underflow and out-of-bounds access, causing a panic that denies service to Git clients during fetch or clone operations. This pre-authentication DoS requires no credentials and can be triggered over the network.
GHSA-2vh6-hw4j-32ww
MEDIUM
[gix-packetline] A panic occurs when receiving a side-band packet with only a band-id byte and empty payload, allowing a malicious Git server to trigger a denial of service during fetch operations. This is a pre-authentication, network-triggered crash affecting any client cloning or fetching from an attacker-controlled remote.
AIKIDO-2026-10922
MEDIUM
[http] A panic-safety flaw in HeaderMap::IntoIter::drop can cause double-free memory corruption when a value's destructor panics during iterator draining. This could lead to process crashes, denial of service, or undefined behavior with potential security impact.
AIKIDO-2025-10839
LOW
[http] A panic vulnerability in the HeaderMap::try_reserve method causes an integer overflow when processing crafted input, violating Rust's try_* convention and crashing the application. This leads to denial of service as attackers can trigger the panic with sufficiently large inputs.

@cst8t
cst8t merged commit 4db1cf4 into v0.12.1-develop Oct 4, 2026
2 checks passed
@cst8t
cst8t deleted the fix/aikido-security-update-packages-133378994-8nr4 branch October 4, 2026 16:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant