Skip to content

security: update rmcp to fix quinn-udp DoS vulnerability #411

@bug-ops

Description

@bug-ops

Related to #391

Summary

RUSTSEC-2025-0005: quinn-udp versions before 0.5.9 have a potential denial-of-service vulnerability. Our dependency via rmcpquinnquinn-udp 0.5.8 affects MCP HTTP transport.

Severity

Medium — DoS vector exists in MCP client (admin-controlled servers limit risk).

Location

Transitive: zeph → rmcp 0.14.2 → quinn 0.11.7 → quinn-udp 0.5.8

Recommendation

Update rmcp to a version that depends on quinn-udp >= 0.5.9.

If unavailable, add temporary ignore:

[[advisories.ignore]]
id = "RUSTSEC-2025-0005"
reason = "waiting for rmcp upgrade, MCP servers admin-controlled"

References

Metadata

Metadata

Assignees

No one assigned

    Labels

    securitySecurity hardening

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions