logo

Unpatched XRING Flaw in XQUIC Lets Remote Clients Crash HTTP/3 Servers

ID: 404e44d5-c674-58c8-b5e6-ffefdd0596d5

STIX ID: report--404e44d5-c674-58c8-b5e6-ffefdd0596d5

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2026-07-10

Date Updated: 2026-07-18

Author: [email protected] (The Hacker News)

...
...

FoxIO disclosed XRING, a vulnerability in Alibaba's XQUIC (affecting all releases through v1.9.4) where a single incorrect size calculation during QPACK dynamic-table growth can let an unauthenticated remote client crash the server using ordinary HTTP/3 traffic; there is no patch or CVE yet, and operators can only mitigate by disabling the QPACK dynamic table or HTTP/3.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.