1mo ago · hacker-news
A critical unpatched vulnerability dubbed XRING in Alibaba's XQUIC library allows remote clients to crash HTTP/3 servers using legitimate QPACK traffic. The flaw stems from an integer underflow during dynamic table resizing in QPACK, leading to out-of-bounds memory copy and server crash. The vulnerability affects all XQUIC versions up to v1.9.4 and impacts servers using HTTP/3 with default QPACK settings, including those behind Alibaba's Tengine web server. No patch or CVE has been assigned as of July 10, 2026.