vulnerability Unpatched XRING Flaw in XQUIC Lets Remote Clients Crash HTTP/3 Servers A remote client can crash HTTP/3 servers running XQUIC, Alibaba's HTTP/3 and QUIC library. The vulnerability, dubbed XRING, stems from an incorrect size calculation during table resizing within the QPACK header compression mechanism. No patch is available, and the issue affects all versions through v1.9.4. While no exp… The Hacker News · Jul 10, 2026 High CVE-2026-42530httphttp3quic
threat-intel The browser blind spot: Why your security tool may not be blocking what you think it is [Guest Diary], (Wed, Jun 17th) This article highlights a significant security gap in Cloud Access Security Broker (CASB) deployments due to the increasing use of the QUIC protocol. CASBs, traditionally designed to inspect TCP traffic, fail to detect w… SANS Internet Storm Center · Jun 17, 2026 High quiccasbssl