CVE-2026-42530
CVSS 8.1 HIGH: nGINX Open Source has a vulnerability in the ngx_http_v3_module module.
Vulnerabilities · 66 days ago
Any server embedding XQUIC can be knocked over by a single standards-compliant HTTP/3 request. The failure happens before login, and the usual response of patching is incomplete because there is no fixed release yet, so availability risk extends past Alibaba deployments to anyone shipping the library with default QPACK settings.
FoxIO’s disclosure on July 8 ties the issue to XQUIC through v1.9.4 and says about 260 bytes of legal QPACK traffic can crash the process. The affected surface includes Tengine and other HTTP/3 deployments that inherit XQUIC, plus NGINX Open Source installations that depend on the same module path.
The temporary workaround is to disable QPACK’s dynamic table or drop HTTP/3 support. Until a real fix ships, the practical risk is not data theft but remote service interruption from ordinary traffic that passes protocol checks.
CVSS 8.1 HIGH: nGINX Open Source has a vulnerability in the ngx_http_v3_module module.
1 source covering this story
Unpatched XRING Flaw in XQUIC Lets Remote Clients Crash HTTP/3 Servers
FoxIO disclosed XRING, an unpatched XQUIC flaw that lets unauthenticated clients crash HTTP/3 servers with 260 bytes of legal QPACK traffic.
Part of the PlainSec briefing for 2026-07-11