HomeSecurityXRING: Serious bug in XQUIC threatens HTTP/3 servers

XRING: Serious bug in XQUIC threatens HTTP/3 servers

A particularly serious security flaw has been found in the XQUIC, Alibaba's open-source solution for the QUIC and HTTP/3 protocols. According to security researcher Sébastien Féry of FoxIO, an error in a single variable in the code allows a remote user to cause a server to crash, without requiring account compromise, malicious packets, or special exploit techniques. The vulnerability, dubbed XRING, was disclosed on July 8 and stands out because it is triggered by perfectly valid network traffic. A small data sequence of about 260 bytes, based on the QPACK protocol, is enough to cause the server process to terminate.

Article Image: Unpatched XRING Flaw in XQUIC Lets Remote Clients Crash HTTP/3 Servers

Who is affected?

The problem is not limited to Alibaba services. Because XQUIC is available as open source software, any organization that has integrated it into HTTP/3 servers is at risk of being affected.

Interestingly, the library is also used by Tengine , Alibaba's Nginx -based web server that serves large-scale cloud and CDN services . Among them are popular platforms such as Taobao and Alipay , which highlights the importance of the vulnerability for the entire HTTP/3 ecosystem.

So far, all versions up to the most recent, v1.9.4, are affected, while at the time of the discovery of the problem there was no patch available nor had a CVE identifier been issued.

See also: Critical flaw in Apache HTTP/2 allows DoS and RCE

How the error is generated

The cause of the problem lies in the way HTTP/3 handles HTTP header compression via QPACK. This protocol uses a dynamic table to avoid sending the same information repeatedly, thus improving connection performance.

XQUIC stores this data in a ring buffer. When the array needs more capacity, the library creates new memory space and moves the already stored data there.

In one particular case of reallocation, however, the code incorrectly uses the capacity of the new buffer instead of the old one to calculate how much data to copy. The result is a serious overestimation of the copy size, which then leads to an integer underflow. This incorrect value translates into a huge memory copy length, causing an out-of-bounds write and ultimately crashing the application.

The most worrying aspect is that the attacker does not need to break any protocol rules. All commands sent are considered perfectly valid by HTTP/3, which makes the attack extremely difficult to detect by conventional protection systems.

XRING: Serious bug in XQUIC threatens HTTP/3 servers

Temporary solutions until a fix patch is released

Until an official security update is available, system administrators are advised to take temporary protective measures. The main recommendation is to disable the QPACK dynamic table via the SETTINGS_QPACK_MAX_TABLE_CAPACITY with a value of 0, thus limiting the possibility of triggering the vulnerability.

In environments where security is a top priority, it is even recommended to temporarily disable HTTP/3 supportuntil a fixed version of the library is released. Although this option may affect service performance, it significantly reduces the risk of a remote DoS attack.

A fresh reminder of the dangers of modern protocols

XRING is not an isolated incident. In recent years, cybersecurity researchers have identified several vulnerabilities in implementations of the HTTP/2 and HTTP/3 protocols, mainly in the compression mechanisms of HTTP headers.

Just a few weeks before the XRING revelation, a serious vulnerability in NGINX's HTTP/3 code, which also allowed remote server crashing via the same QPACK encoder stream, although it relied on a different type of error.

See also: Prompt Injection Flaw in Vanna AI Exposes Databases to RCE Attacks

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

A similar case was reported in June with the “HTTP/2 Bomb” attack, which exploited the HPACK protocol to cause a denial of service on popular web servers such as Nginx, Apache, IIS, and Envoy. HAProxy patched two separate QUIC vulnerabilities earlier this year that were also related to integer underflow.

Why is XRING considered particularly dangerous?

What differentiates XRING from many other vulnerabilities is that it does not require malicious packets or a violation of protocol specifications. The attacker uses only valid data, which any compliant server would consider normal.

This approach makes it significantly more difficult for security systems, as the network traffic appears perfectly legitimate. Although FoxIO only demonstrated causing a server crash and not executing arbitrary code, experts point out that any bug that causes an out-of-memory write requires special attention, as it may lead to more complex forms of exploitation in the future.

XRING: Serious bug in XQUIC threatens HTTP/3 servers

Alibaba's stance and next moves

According to FoxIO, the researcher attempted to contact Alibaba as early as April, following the responsible vulnerability disclosure. However, despite repeated attempts to contact him, he did not receive a response before he proceeded to publicly disclose the issue.

So far, it has not been confirmed that the vulnerability has been exploited in real attacks, and it remains unknown when the fixed version of XQUIC will be released.

See also: New DoS attack on HTTP/2 protocol brings down servers

The XRING case is yet another reminder that even a small programming error can have serious consequences for software used by millions of users and large web services. As HTTP/3 is increasingly adopted by cloud providers and modern web applications, the security of the libraries that implement it becomes critical.

Until an official patch is available, organizations using XQUIC are urged to immediately review the recommended mitigations, monitor relevant security advisories, and increase monitoring of their HTTP/3 services. Early response can be critical to avoiding downtime and potential impacts to the reliability of their infrastructure.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS