Security

Audited against 200+ issues from aioquic and quiche. Zero unsafe blocks.

Mitigations Applied

AttackMitigationSource
ACK range DoSMax 256 ACK ranges per frameaioquic #549
CRYPTO buffer OOM128KB cap per connectionaioquic #501
Undersized InitialReject packets < 1200 bytesRFC 9000 §14.1
Oversized frames16MB payload capInternal audit
Predictable CIDsMixed entropy + atomic counterInternal audit
Mutex poisoningGraceful lock().ok() in I/O loopInternal audit
Stateless reset oracleConstant-time token comparisonaioquic #555
Idle timeout mismatchmin(local, remote) per RFCaioquic #466

Design Principles