Wire · regulatory
Unpatched XRING Vulnerability in XQUIC Exposes HTTP/3 Servers to Remote Crash Risk
◆ Sectors
◆ Geography
◆ Source
◆ Verified
Fusion42 · 12 July 2026 · Fusion42 review
An unpatched memory corruption vulnerability (XRING) in Alibaba's XQUIC HTTP/3 library allows remote unauthenticated clients to crash servers with 260 bytes of valid QPACK traffic; all versions through v1.9.4 are affected, including Alibaba's Tengine web server used by Taobao, Alipay, and Alibaba Cloud, with no patch available as of July 2026.
This Wire brief sits within Fusion42's coverage of Cloud Infrastructure and Cybersecurity.
◆ ◆ The Wire takeaway
If you're running HTTP/3 on XQUIC, you're exposed to remote crash with a single small packet—disable dynamic QPACK compression today or turn off HTTP/3 entirely until Alibaba releases a patch. Anyone relying on Alibaba's Tengine or any XQUIC integration needs to move now, not wait for the CVE.
◆ Coverage
1 source · 12 Jul 2026
◆ Related on Wire
◆ Topics