Unpatched XRING Flaw in XQUIC Lets Remote Clients Crash HTTP/3 Servers 20%

By The Hacker News36%

7/10/2026, 6:09:19 AM

BS Summary: This article contains 30 faulty reasoning types, including Overconfidence Bias, Post Hoc (False Cause), and Availability Heuristic, with Appeal to Authority as the most egregious example at 9.8% saturation with 105 hits. Analysis detected 1,431 faulty-reasoning hits from 1,075 analyzed words, generating a BS Score of 34.6% and a BS Rank of 20% (17,524 of 21,887 articles). This article is better (less manipulative) than 80.10% of the article peer group.

Unpatched XRING Flaw in XQUIC Lets Remote Clients Crash HTTP/3 Servers 
 Swati Khandelwal  Jul 10, 2026 Vulnerability / Server Security 
A single wrong variable on one line in XQUIC, Alibaba's QUIC and HTTP/3 library, lets any remote client crash the server with a short burst of completely legal traffic. 
There is no patch. 
FoxIO researcher Sébastien Féry disclosed the flaw on July 8 and nicknamed it XRING. 
He says it needs no login and no malformed packets: about 260 bytes of ordinary QPACK traffic takes the server process down. 
XQUIC is open-source, so the risk is not Alibaba's alone: any server that embeds it and serves HTTP/3 with the default QPACK settings is exposed. 
That includes Tengine, Alibaba's Nginx-based web server, which FoxIO says fronts the company's cloud and CDN on sites including Taobao and Alipay. 
Every release through v1.9.4, the latest, is affected. 
There is no fixed release and no CVE as of July 10. 
Until a fix ships, operators can set SETTINGS_QPACK_MAX_TABLE_CAPACITY to 0, which turns off QPACK's dynamic table, or drop HTTP/3 support entirely. 
The bug lives in how HTTP/3 compresses headers. 
To avoid sending the same header (say, user-agent) over and over, HTTP/3 uses QPACK. 
It keeps a shared table that the client directs the server to build up and resize through a dedicated control channel, the encoder stream. 
XQUIC stores that table's bytes in a ring buffer , a fixed block of memory where data wraps from the end back to the start once it fills. 
When the client asks to grow the table, XQUIC allocates a bigger buffer and copies the old data across. 
That copy has four cases, depending on whether the data wraps in the old buffer, the new one, both, or neither. 
In one of them, the code sizes the leftover tail data against the new, larger buffer's capacity instead of the old one's. 
It overcounts badly. 
Grow a 64-byte table with the write cursor near the end, and resize to 65, and XQUIC decides there are 70 tail bytes to move when there are really 6. 
That wrong number flows into a memory copy. 
The copy length comes from subtracting the overcount from a smaller value. 
Because that length is an unsigned size_t, it underflows and wraps to a near-maximum number, and the copy runs off the end of memory. 
In FoxIO's release build on Ubuntu 26.04, glibc's _FORTIFY_SOURCE=2 caught the bad length and killed the process. 
Without that check, the copy writes out of bounds, from the old buffer past the end of the new one. 
Féry showed a crash but did not test whether that corruption could be exploited further. 
None of the values in the attack breaks QPACK's rules. 
XQUIC advertises a 16 KiB dynamic-table limit by default; the payload asks for 64 bytes, then 65. 
The client only has to drive the table into the exact wrapped layout that hits the faulty branch. 
FoxIO says the mistake has been in XQUIC since its first public release in January 2022, and a proof of concept is public . 
XRING is the latest in a string of remote crashes in HTTP/2 and HTTP/3 stacks. 
Three weeks earlier, THN reported a use-after-free in NGINX's HTTP/3 module (CVE-2026-42530) that a remote, unauthenticated client could reach through the same QPACK encoder stream XRING abuses, a different bug class on the same attack surface. 
In June, Calif's HTTP/2 Bomb caused remote denial of service against Nginx, Apache, IIS, and Envoy by abusing HPACK, HTTP/2's header compression, and the predecessor to QPACK. 
In February, HAProxy patched two QUIC crashes , one an integer underflow during token validation, the same type of bug behind XRING, though it needed a malformed packet where XRING needs none. 
That difference is the point: legal input, one arithmetic slip, a dead server. 
FoxIO demonstrated a crash, not code execution, and reported no exploitation in the wild. 
It says it emailed Alibaba on April 7 through the project's security policy, which promises a reply within three working days, then followed up four more times through May 9 without an answer before going public. 
The Hacker News has asked Alibaba whether a fix and a CVE are coming, and whether FoxIO's five disclosure attempts reached its security team. 
It has asked FoxIO whether the flaw has been exploited in the wild and whether the underlying heap write can be pushed past a crash. 
The story will be updated with any response. 
Found this article interesting? 
Follow us on Google News , Twitter and LinkedIn to read more exclusive content we post. 
Application Security , Cloud security , denial of service , network security , Open Source , Patch Management , server security , Vulnerability , Web Security 
ThreatsDay: AI Compute Hijacking, Apple Email Flaw, BlueHammer Ransomware + 14 Stories 
Chrome Ad Blocker with 10M+ Installs Found with Dormant Script Injection Capability 
New DirtyClone Linux Kernel Flaw Lets Local Users Gain Root via Cloned Packets 
Amazon Q Developer Flaw Could Let Malicious Repos Run Code via MCP Configs 
New Linux pedit COW Exploit Enables Root Access by Poisoning Cached Binaries 
OpenAI Previews GPT-5.6 Sol With Restricted Access and Stronger Cyber Safeguards 
FBI Warns Russian Intelligence Hackers Target Signal Backup Recovery Keys 
Public PoC Released for Critical libssh2 CVE-2026-55200 Client-Side SSH Flaw 
Microsoft Removes 119 Edge Extensions That Hid Malware in Images and Fonts 
 Weekly Recap: Linux Kernel Flaws, AI Malware Tricks, Turla Backdoor, Infostealers and More 
Mustang Panda Uses Zoho WorkDrive as Command Channel in Indian Government Attacks 
WhatsApp is Finally Getting Usernames to Help Keep Phone Numbers Private 
Oracle E-Business Suite Flaw CVE-2026-46817 Actively Exploited in the Wild 
New BioShocking Attack Tricks AI Browsers Into Leaking User Credentials 
AirDrop and Quick Share Flaws Let Nearby Attackers Trigger Crashes and Bypass Checks 
282 iOS AI Apps Leak API Keys and Open AI Proxy Access in Network Traffic Study 
GuardFall Exposes Open-Source AI Coding Agents to Decades-Old Shell Injection Risks 
Microsoft Warns Poisoned MCP Tool Descriptions Can Make AI Agents Leak Data 
RustDuck Botnet Rebuilds in Rust to Hijack Routers and Servers for DDoS 
 Featured Resources 
What 200+ Security Teams Reveal About Using IP Intelligence in 2026 
Get Hands-On SANS Training for Today’s Cyber Defense and Offensive Security Challenges 
See What’s Really Exposed Across Your IT, OT, IoT, Cloud, and Mobile Assets 
Get Gartner’s Guide to AI Agent Supervision and Runtime Controls 
Article reasoning-pattern comparisonThis article: 2.2%The Hacker News: 1.8%The Hacker News: 1.9%Confirmation Bias2.2%This article: 0.0%The Hacker News: 0.8%The Hacker News: 1.2%Anchoring Bias0.0%This article: 8.5%The Hacker News: 3.5%The Hacker News: 3.3%Availability Heuristic8.5%This article: 5.4%The Hacker News: 1.5%The Hacker News: 1.5%Representativeness Heuristic5.4%This article: 1.4%The Hacker News: 0.3%The Hacker News: 0.6%Hindsight Bias1.4%This article: 9.2%The Hacker News: 2.7%The Hacker News: 2.5%Overconfidence Bias9.2%This article: 6.0%The Hacker News: 2.8%The Hacker News: 2.7%Framing Effect6.0%This article: 6.5%The Hacker News: 1.3%The Hacker News: 1.0%Loss Aversion6.5%This article: 3.3%The Hacker News: 0.6%The Hacker News: 0.6%Status Quo Bias3.3%This article: 0.0%The Hacker News: 0.1%The Hacker News: 0.1%Sunk Cost Effect0.0%This article: 2.7%The Hacker News: 1.4%The Hacker News: 1.3%Optimism Bias2.7%This article: 2.8%The Hacker News: 1.4%The Hacker News: 1.6%Pessimism Bias2.8%This article: 7.3%The Hacker News: 6.6%The Hacker News: 6.7%Negativity Bias7.3%This article: 3.3%The Hacker News: 1.5%The Hacker News: 0.8%Self-Serving Bias3.3%This article: 0.0%The Hacker News: 0.3%The Hacker News: 0.4%Fundamental Attribution Error0.0%This article: 0.0%The Hacker News: 0.0%The Hacker News: 0.1%Actor-Observer Bias0.0%This article: 0.0%The Hacker News: 0.1%The Hacker News: 0.1%In-Group Bias0.0%This article: 1.1%The Hacker News: 0.1%The Hacker News: 0.3%Out-Group Homogeneity Bias1.1%This article: 3.2%The Hacker News: 0.8%The Hacker News: 0.6%Halo Effect3.2%This article: 0.0%The Hacker News: 0.0%The Hacker News: 0.0%Horn Effect0.0%This article: 0.0%The Hacker News: 0.0%The Hacker News: 0.0%Dunning-Kruger Effect0.0%This article: 5.6%The Hacker News: 1.0%The Hacker News: 1.5%Recency Bias5.6%This article: 1.3%The Hacker News: 0.3%The Hacker News: 0.3%Primacy Effect1.3%This article: 0.0%The Hacker News: 0.1%The Hacker News: 0.1%Blind-Spot Bias0.0%This article: 0.0%The Hacker News: 0.1%The Hacker News: 0.1%Ad Hominem0.0%This article: 0.0%The Hacker News: 0.2%The Hacker News: 0.1%Straw Man0.0%This article: 9.8%The Hacker News: 3.7%The Hacker News: 4.0%Appeal to Authority9.8%This article: 2.0%The Hacker News: 2.4%The Hacker News: 1.6%False Dilemma2.0%This article: 0.0%The Hacker News: 0.4%The Hacker News: 0.5%Slippery Slope0.0%This article: 0.0%The Hacker News: 0.1%The Hacker News: 0.1%Circular Reasoning0.0%This article: 6.3%The Hacker News: 5.1%The Hacker News: 4.3%Hasty Generalization6.3%This article: 0.0%The Hacker News: 0.0%The Hacker News: 0.1%Red Herring0.0%This article: 2.1%The Hacker News: 0.3%The Hacker News: 0.2%Bandwagon2.1%This article: 7.8%The Hacker News: 1.3%The Hacker News: 1.1%Appeal to Emotion7.8%This article: 0.0%The Hacker News: 0.9%The Hacker News: 0.5%Begging the Question0.0%This article: 9.2%The Hacker News: 1.8%The Hacker News: 1.9%Post Hoc (False Cause)9.2%This article: 0.0%The Hacker News: 0.0%The Hacker News: 0.0%Tu Quoque0.0%This article: 3.3%The Hacker News: 0.4%The Hacker News: 0.6%Burden of Proof3.3%This article: 0.0%The Hacker News: 0.2%The Hacker News: 0.1%Appeal to Nature0.0%This article: 2.3%The Hacker News: 0.5%The Hacker News: 0.3%Composition/Division2.3%This article: 2.0%The Hacker News: 1.2%The Hacker News: 1.0%Anecdotal2.0%This article: 0.0%The Hacker News: 0.1%The Hacker News: 0.1%No True Scotsman0.0%This article: 3.2%The Hacker News: 1.3%The Hacker News: 2.3%Ambiguity (Equivocation)3.2%This article: 0.0%The Hacker News: 0.0%The Hacker News: 0.0%Gambler’s Fallacy0.0%This article: 0.0%The Hacker News: 0.1%The Hacker News: 0.0%Middle Ground0.0%This article: 0.0%The Hacker News: 0.0%The Hacker News: 0.0%Personal Incredulity0.0%This article: 0.0%The Hacker News: 0.1%The Hacker News: 0.1%Special Pleading0.0%This article: 0.0%The Hacker News: 0.0%The Hacker News: 0.1%Genetic Fallacy0.0%This article: 7.4%The Hacker News: 0.8%The Hacker News: 1.4%Unattributed Quote7.4%This article: 0.0%The Hacker News: 0.3%The Hacker News: 0.9%Quote-first Misdirection0.0%This article: 2.7%The Hacker News: 1.9%The Hacker News: 2.3%Biased Writer Voice2.7%This article: 0.4%The Hacker News: 5.0%The Hacker News: 4.4%Indoctrination0.4%This article: 0.0%The Hacker News: 0.0%The Hacker News: 0.0%Politically Left Leaning Bias0.0%This article: 0.0%The Hacker News: 0.0%The Hacker News: 0.0%Politically Right Leaning Bias0.0%This article: 4.7%The Hacker News: 6.7%The Hacker News: 3.0%Attempt to Sell a Product or S…4.7%

1075 words analyzed.

Speakers

7speakers27%attributed speech785writer words
Voice mapSelect a segment to jump to its words
Writer's voice • 11 words • 0.0% coverageWriter's voice • 11 words • 0.0% coverageSwati Khandelwal • 11 words • 0.0% coverageWriter's voice • 29 words • 100.0% coverageWriter's voice • 4 words • 0.0% coverageFoxIO • 14 words • 0.0% coverageSébastien Féry • 22 words • 100.0% coverageWriter's voice • 25 words • 0.0% coverageFoxIO • 22 words • 100.0% coverageWriter's voice • 8 words • 0.0% coverageWriter's voice • 12 words • 0.0% coverageWriter's voice • 21 words • 0.0% coverageWriter's voice • 8 words • 0.0% coverageWriter's voice • 14 words • 0.0% coverageWriter's voice • 24 words • 0.0% coverageWriter's voice • 28 words • 0.0% coverageWriter's voice • 19 words • 0.0% coverageWriter's voice • 21 words • 0.0% coverageWriter's voice • 22 words • 0.0% coverageWriter's voice • 3 words • 0.0% coverageWriter's voice • 30 words • 0.0% coverageWriter's voice • 8 words • 0.0% coverageWriter's voice • 12 words • 0.0% coverageWriter's voice • 24 words • 0.0% coverageFoxIO • 17 words • 0.0% coverageWriter's voice • 20 words • 0.0% coverageSébastien Féry • 15 words • 0.0% coverageWriter's voice • 10 words • 0.0% coverageWriter's voice • 17 words • 0.0% coverageWriter's voice • 18 words • 0.0% coverageFoxIO • 24 words • 0.0% coverageWriter's voice • 15 words • 0.0% coverageWriter's voice • 36 words • 0.0% coverageWriter's voice • 27 words • 0.0% coverageHAProxy • 32 words • 0.0% coverageWriter's voice • 13 words • 0.0% coverageFoxIO • 14 words • 0.0% coverageFoxIO • 36 words • 100.0% coverageThe Hacker News • 24 words • 0.0% coverageThe Hacker News • 25 words • 0.0% coverageWriter's voice • 8 words • 0.0% coverageWriter's voice • 4 words • 100.0% coverageWriter's voice • 16 words • 100.0% coverageWriter's voice • 26 words • 0.0% coverageWriter's voice • 12 words • 0.0% coverageWriter's voice • 12 words • 0.0% coverageWriter's voice • 13 words • 0.0% coverageWriter's voice • 13 words • 0.0% coverageWriter's voice • 12 words • 0.0% coverageWriter's voice • 11 words • 0.0% coverageFBI • 10 words • 0.0% coverageWriter's voice • 10 words • 0.0% coverageMicrosoft • 12 words • 0.0% coverageWriter's voice • 14 words • 0.0% coverageWriter's voice • 12 words • 0.0% coverageWriter's voice • 11 words • 0.0% coverageWriter's voice • 10 words • 0.0% coverageWriter's voice • 10 words • 0.0% coverageWriter's voice • 13 words • 0.0% coverageWriter's voice • 16 words • 0.0% coverageWriter's voice • 11 words • 0.0% coverageMicrosoft • 12 words • 0.0% coverageWriter's voice • 12 words • 0.0% coverageWriter's voice • 3 words • 0.0% coverageWriter's voice • 11 words • 0.0% coverageWriter's voice • 12 words • 100.0% coverageWriter's voice • 13 words • 100.0% coverageWriter's voice • 10 words • 100.0% coverage
Selected voice

FoxIO

100%flagged-word coverage
127 attributed words44% of attributed speech66% writer coverage
0%25.0%50.0%Unattributed Quote+45.7 ptsWriter: 0.0%FoxIO: 45.7%45.7%Attempt to Sell a Product -6.5 ptsWriter: 6.5%FoxIO: 0.0%0.0%Biased Writer Voice-3.7 ptsWriter: 3.7%FoxIO: 0.0%0.0%Indoctrination-0.5 ptsWriter: 0.5%FoxIO: 0.0%0.0%

Attribution is sentence-level. Pattern percentages are calculated only from words assigned to that voice.

Loading…
Loading…
Loading…
Loading…

Analysis

Hover over highlighted words in the article to view the associated bias or fallacy analysis.