Unpatched XRING Flaw in XQUIC Lets Remote Clients Crash HTTP/3 Servers
ResearchXQUICTengineOur summary
A critical vulnerability dubbed XRING in Alibaba's XQUIC library enables remote clients to crash HTTP/3 servers using standard traffic. Discovered by FoxIO researcher Sébastien Féry, the flaw affects all versions up to v1.9.4 and impacts products like Tengine. The issue stems from a miscalculation in handling QPACK header compression, leading to memory corruption and server termination. Despite being disclosed on July 8, no patch or CVE has been issued as of July 10. Operators are advised to disable QPACK or HTTP/3 until a fix is available.
The Hacker News publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.