CVE Tools
Back to feed
Research XQUIC network-edge Tengine Alibaba rce

Unpatched XRING Flaw in XQUIC Lets Remote Clients Crash HTTP/3 Servers

The Hacker News·By The Hacker News··4 min read
CVE Tools coverage

A critical vulnerability dubbed XRING in Alibaba's XQUIC library enables remote clients to crash HTTP/3 servers using standard traffic. Discovered by FoxIO researcher Sébastien Féry, the flaw affects all versions up to v1.9.4 and impacts products like Tengine. The issue stems from a miscalculation in handling QPACK header compression, leading to memory corruption and server termination. Despite being disclosed on July 8, no patch or CVE has been issued as of July 10. Operators are advised to disable QPACK or HTTP/3 until a fix is available.