CVE-2026-1788

Source
https://cve.org/CVERecord?id=CVE-2026-1788
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-1788.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-1788
Downstream
Published
2026-02-03T03:22:48.256Z
Modified
2026-07-22T03:08:33.623132Z
Severity
  • 6.6 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/AU:Y/R:U/RE:M/U:Amber CVSS Calculator
Summary
Buffer Overflow in Xquic Server
Details

: Out-of-bounds Write vulnerability in Xquic Project Xquic Server xquic on Linux (QUIC protocol implementation, packet processing module modules) allows : Buffer Manipulation.This issue affects Xquic Server: through 1.8.3.

Database specific
{
    "cwe_ids": [
        "CWE-787"
    ],
    "cna_assigner": "alibaba",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/1xxx/CVE-2026-1788.json"
}
References

Affected packages

Git / github.com/alibaba/xquic

Affected ranges

Type
GIT
Repo
https://github.com/alibaba/xquic
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "1.8.3"
        },
        {
            "fixed": "1.8.3"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "DESCRIPTION"
    ]
}

Affected versions

stable-1.*
stable-1.0.0
stable-1.0.1
v1.*
v1.1.0-beta.1
v1.1.0-beta.2
v1.1.0-stable
v1.2.0-stable
v1.3.0-beta
v1.4.0
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.2

Database specific

vanir_signatures_modified
"2026-07-22T03:08:33Z"
vanir_signatures
[
    {
        "signature_type": "Function",
        "deprecated": false,
        "digest": {
            "length": 2337.0,
            "function_hash": "164270084054266829095062343711874293474"
        },
        "signature_version": "v1",
        "source": "https://github.com/alibaba/xquic/commit/994040ae7da4b0e8c754785329efad0286a74ff7",
        "id": "CVE-2026-1788-1b5cedc6",
        "target": {
            "function": "xqc_conn_send_path_challenge",
            "file": "src/transport/xqc_conn.c"
        }
    },
    {
        "signature_type": "Line",
        "deprecated": false,
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "50750606295519904077741833633600929969",
                "263881402770105293961678263567629116746",
                "136276185250294421830414333886500578580",
                "163548359958201530341781450396301979075",
                "319765355248818241322258662798619738932",
                "326092539481173590229044099306561843506",
                "83439187831266406403783256113035635298"
            ]
        },
        "signature_version": "v1",
        "source": "https://github.com/alibaba/xquic/commit/994040ae7da4b0e8c754785329efad0286a74ff7",
        "id": "CVE-2026-1788-5e5c32d5",
        "target": {
            "file": "src/transport/xqc_packet_parser.c"
        }
    },
    {
        "signature_type": "Line",
        "deprecated": false,
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "148872026431240894980384883080321048000",
                "171181699033522412296449299841298924505",
                "183868167876057872337389116681433765061",
                "10732616816964447794894307321813389729"
            ]
        },
        "signature_version": "v1",
        "source": "https://github.com/alibaba/xquic/commit/994040ae7da4b0e8c754785329efad0286a74ff7",
        "id": "CVE-2026-1788-64d1364a",
        "target": {
            "file": "src/transport/xqc_send_ctl.h"
        }
    },
    {
        "signature_type": "Line",
        "deprecated": false,
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "85635896859501040122003627024492034999",
                "262083635511637407996104029407028349247",
                "176762060474349321045714908550000679880",
                "256935870964048835881908201647840522505",
                "7691198956187540316633415863949597823",
                "209183633441136550193934349773566520033",
                "68226778162799630125950850179900630843",
                "272088445861657690468676912773323159921",
                "134317152380928198697540318101678247276",
                "68804187325661430269431852649691818121",
                "297900329069601932376053727166782474829",
                "97351260434336212845123820277964926093",
                "296639031101067366802632363305681209730",
                "128936157933126768496852763127785316123",
                "242310168248476389538097083546747853607",
                "331756364964420592886285681985156136658",
                "171015835410304252999536095241897903195",
                "216781747469656665851941002008963946577",
                "8415070932288880548360905847487924159",
                "301439052205705684279296409077176866895",
                "21784661247402294681152557043112418640",
                "15502402594705666811752119122906316144",
                "236018555112522560041892280290034653825",
                "21515157666818781226237867762226171506",
                "299082190596347549481976995936569190701"
            ]
        },
        "signature_version": "v1",
        "source": "https://github.com/alibaba/xquic/commit/994040ae7da4b0e8c754785329efad0286a74ff7",
        "id": "CVE-2026-1788-7cc994ee",
        "target": {
            "file": "src/transport/xqc_conn.c"
        }
    },
    {
        "signature_type": "Line",
        "deprecated": false,
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "302800498696157906437094485473860771392",
                "17546480891272246732393101613410724923",
                "80055743523724658224446174073342425399",
                "255881348701976652531320182033655063212",
                "240915324728614614098266518523548477712",
                "180801651035280835518452859331351481",
                "147252815417482834272058158991510345948",
                "172311276783258225635398220954988194363",
                "210014540126848960732663653767050714849",
                "181278238598280759914603890909816499566"
            ]
        },
        "signature_version": "v1",
        "source": "https://github.com/alibaba/xquic/commit/994040ae7da4b0e8c754785329efad0286a74ff7",
        "id": "CVE-2026-1788-8cf1cdda",
        "target": {
            "file": "src/transport/xqc_send_ctl.c"
        }
    },
    {
        "signature_type": "Function",
        "deprecated": false,
        "digest": {
            "length": 351.0,
            "function_hash": "26937901930384364992600909254141896407"
        },
        "signature_version": "v1",
        "source": "https://github.com/alibaba/xquic/commit/994040ae7da4b0e8c754785329efad0286a74ff7",
        "id": "CVE-2026-1788-95c78f4b",
        "target": {
            "function": "xqc_packet_decode_packet_number",
            "file": "src/transport/xqc_packet_parser.c"
        }
    },
    {
        "signature_type": "Function",
        "deprecated": false,
        "digest": {
            "length": 952.0,
            "function_hash": "35795793281428787951321097761314646286"
        },
        "signature_version": "v1",
        "source": "https://github.com/alibaba/xquic/commit/994040ae7da4b0e8c754785329efad0286a74ff7",
        "id": "CVE-2026-1788-9e644a79",
        "target": {
            "function": "xqc_conn_enc_packet",
            "file": "src/transport/xqc_conn.c"
        }
    },
    {
        "signature_type": "Line",
        "deprecated": false,
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "235905036223444961291746567897729390068",
                "237322328265094867051207392262695663820",
                "314066912628745206459531088021067799495",
                "320731618866375677112756506275501027711"
            ]
        },
        "signature_version": "v1",
        "source": "https://github.com/alibaba/xquic/commit/994040ae7da4b0e8c754785329efad0286a74ff7",
        "id": "CVE-2026-1788-c34f87a4",
        "target": {
            "file": "include/xquic/xquic.h"
        }
    },
    {
        "signature_type": "Function",
        "deprecated": false,
        "digest": {
            "length": 965.0,
            "function_hash": "257804467467975622754312289046032337537"
        },
        "signature_version": "v1",
        "source": "https://github.com/alibaba/xquic/commit/994040ae7da4b0e8c754785329efad0286a74ff7",
        "id": "CVE-2026-1788-ebb6f8fe",
        "target": {
            "function": "xqc_enc_packet_with_pn",
            "file": "src/transport/xqc_conn.c"
        }
    },
    {
        "signature_type": "Function",
        "deprecated": false,
        "digest": {
            "length": 1361.0,
            "function_hash": "304202060413209124653321740827291180700"
        },
        "signature_version": "v1",
        "source": "https://github.com/alibaba/xquic/commit/994040ae7da4b0e8c754785329efad0286a74ff7",
        "id": "CVE-2026-1788-ef1f78ff",
        "target": {
            "function": "xqc_send_packet_with_pn",
            "file": "src/transport/xqc_conn.c"
        }
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-1788.json"