Input Validation Flaw in XQUIC Product from Alibaba
CVE-2026-6328

8.3HIGH

Key Information:

Status
Vendor
CVE Published:
15 April 2026

What is CVE-2026-6328?

An input validation flaw exists in the XQUIC Project's implementation of the QUIC protocol, specifically within the packet processing and STREAM frame handler modules. This vulnerability may allow attackers to manipulate the protocol by exploiting improper verification of cryptographic signatures, potentially compromising the integrity of communications. Affected versions include XQUIC through 1.8.3.

Affected Version(s)

XQUIC Linux 0 <= 1.8.3

References

CVSS V4

Score:
8.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.