← Back

Wire · regulatory

Unpatched XRING Vulnerability in XQUIC Exposes HTTP/3 Servers to Remote Crash Risk

Published

12 July 2026

Topic

regulatory

Sectors

Cloud InfrastructureCybersecurity

Geography

China

Source

Read at rescana.com

Verified

Fusion42 · 12 July 2026 · Fusion42 review

An unpatched memory corruption vulnerability (XRING) in Alibaba's XQUIC HTTP/3 library allows remote unauthenticated clients to crash servers with 260 bytes of valid QPACK traffic; all versions through v1.9.4 are affected, including Alibaba's Tengine web server used by Taobao, Alipay, and Alibaba Cloud, with no patch available as of July 2026.

This Wire brief sits within Fusion42's coverage of Cloud Infrastructure and Cybersecurity.

◆ The Wire takeaway

If you're running HTTP/3 on XQUIC, you're exposed to remote crash with a single small packet—disable dynamic QPACK compression today or turn off HTTP/3 entirely until Alibaba releases a patch. Anyone relying on Alibaba's Tengine or any XQUIC integration needs to move now, not wait for the CVE.

Coverage

1 source · 12 Jul 2026

Related on Wire

Topics

Cloud InfrastructureCybersecurityhttp3-vulnerabilitydenial-of-servicememory-corruptionqpack-exploitalibaba-xquicunpatched-critical