As cited
Copy frozen at (site build).
vulnerabilities
Unpatched XRING Flaw in XQUIC Lets Remote Clients Crash HTTP/3 Servers
A vulnerability in XQUIC, Alibaba's QUIC and HTTP/3 library, allows unauthenticated remote clients to crash servers with legitimate traffic of approximately 260 bytes. The flaw, disclosed by FoxIO researcher Sébastien Féry and nicknamed XRING, stems from a single incorrect variable assignment and currently has no patch available.
Why it matters: Organizations running XQUIC-based HTTP/3 servers face denial of service risk from any network client; teams should identify affected deployments and assess alternative QUIC implementations or network mitigations until a patch is released.
- Source published
- First seen by Cybersecurity Tracker