: Out-of-bounds Write vulnerability in Xquic Project Xquic Server xquic on Linux (QUIC protocol implementation, packet processing module modules) allows : Buffer Manipulation.This issue affects Xquic Server: through 1.8.3.
{
"cwe_ids": [
"CWE-787"
],
"cna_assigner": "alibaba",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/1xxx/CVE-2026-1788.json"
}"2026-07-22T03:08:33Z"
[
{
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 2337.0,
"function_hash": "164270084054266829095062343711874293474"
},
"signature_version": "v1",
"source": "https://github.com/alibaba/xquic/commit/994040ae7da4b0e8c754785329efad0286a74ff7",
"id": "CVE-2026-1788-1b5cedc6",
"target": {
"function": "xqc_conn_send_path_challenge",
"file": "src/transport/xqc_conn.c"
}
},
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"50750606295519904077741833633600929969",
"263881402770105293961678263567629116746",
"136276185250294421830414333886500578580",
"163548359958201530341781450396301979075",
"319765355248818241322258662798619738932",
"326092539481173590229044099306561843506",
"83439187831266406403783256113035635298"
]
},
"signature_version": "v1",
"source": "https://github.com/alibaba/xquic/commit/994040ae7da4b0e8c754785329efad0286a74ff7",
"id": "CVE-2026-1788-5e5c32d5",
"target": {
"file": "src/transport/xqc_packet_parser.c"
}
},
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"148872026431240894980384883080321048000",
"171181699033522412296449299841298924505",
"183868167876057872337389116681433765061",
"10732616816964447794894307321813389729"
]
},
"signature_version": "v1",
"source": "https://github.com/alibaba/xquic/commit/994040ae7da4b0e8c754785329efad0286a74ff7",
"id": "CVE-2026-1788-64d1364a",
"target": {
"file": "src/transport/xqc_send_ctl.h"
}
},
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"85635896859501040122003627024492034999",
"262083635511637407996104029407028349247",
"176762060474349321045714908550000679880",
"256935870964048835881908201647840522505",
"7691198956187540316633415863949597823",
"209183633441136550193934349773566520033",
"68226778162799630125950850179900630843",
"272088445861657690468676912773323159921",
"134317152380928198697540318101678247276",
"68804187325661430269431852649691818121",
"297900329069601932376053727166782474829",
"97351260434336212845123820277964926093",
"296639031101067366802632363305681209730",
"128936157933126768496852763127785316123",
"242310168248476389538097083546747853607",
"331756364964420592886285681985156136658",
"171015835410304252999536095241897903195",
"216781747469656665851941002008963946577",
"8415070932288880548360905847487924159",
"301439052205705684279296409077176866895",
"21784661247402294681152557043112418640",
"15502402594705666811752119122906316144",
"236018555112522560041892280290034653825",
"21515157666818781226237867762226171506",
"299082190596347549481976995936569190701"
]
},
"signature_version": "v1",
"source": "https://github.com/alibaba/xquic/commit/994040ae7da4b0e8c754785329efad0286a74ff7",
"id": "CVE-2026-1788-7cc994ee",
"target": {
"file": "src/transport/xqc_conn.c"
}
},
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"302800498696157906437094485473860771392",
"17546480891272246732393101613410724923",
"80055743523724658224446174073342425399",
"255881348701976652531320182033655063212",
"240915324728614614098266518523548477712",
"180801651035280835518452859331351481",
"147252815417482834272058158991510345948",
"172311276783258225635398220954988194363",
"210014540126848960732663653767050714849",
"181278238598280759914603890909816499566"
]
},
"signature_version": "v1",
"source": "https://github.com/alibaba/xquic/commit/994040ae7da4b0e8c754785329efad0286a74ff7",
"id": "CVE-2026-1788-8cf1cdda",
"target": {
"file": "src/transport/xqc_send_ctl.c"
}
},
{
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 351.0,
"function_hash": "26937901930384364992600909254141896407"
},
"signature_version": "v1",
"source": "https://github.com/alibaba/xquic/commit/994040ae7da4b0e8c754785329efad0286a74ff7",
"id": "CVE-2026-1788-95c78f4b",
"target": {
"function": "xqc_packet_decode_packet_number",
"file": "src/transport/xqc_packet_parser.c"
}
},
{
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 952.0,
"function_hash": "35795793281428787951321097761314646286"
},
"signature_version": "v1",
"source": "https://github.com/alibaba/xquic/commit/994040ae7da4b0e8c754785329efad0286a74ff7",
"id": "CVE-2026-1788-9e644a79",
"target": {
"function": "xqc_conn_enc_packet",
"file": "src/transport/xqc_conn.c"
}
},
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"235905036223444961291746567897729390068",
"237322328265094867051207392262695663820",
"314066912628745206459531088021067799495",
"320731618866375677112756506275501027711"
]
},
"signature_version": "v1",
"source": "https://github.com/alibaba/xquic/commit/994040ae7da4b0e8c754785329efad0286a74ff7",
"id": "CVE-2026-1788-c34f87a4",
"target": {
"file": "include/xquic/xquic.h"
}
},
{
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 965.0,
"function_hash": "257804467467975622754312289046032337537"
},
"signature_version": "v1",
"source": "https://github.com/alibaba/xquic/commit/994040ae7da4b0e8c754785329efad0286a74ff7",
"id": "CVE-2026-1788-ebb6f8fe",
"target": {
"function": "xqc_enc_packet_with_pn",
"file": "src/transport/xqc_conn.c"
}
},
{
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 1361.0,
"function_hash": "304202060413209124653321740827291180700"
},
"signature_version": "v1",
"source": "https://github.com/alibaba/xquic/commit/994040ae7da4b0e8c754785329efad0286a74ff7",
"id": "CVE-2026-1788-ef1f78ff",
"target": {
"function": "xqc_send_packet_with_pn",
"file": "src/transport/xqc_conn.c"
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-1788.json"