CVE-2026-6328

Source
https://cve.org/CVERecord?id=CVE-2026-6328
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-6328.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-6328
Published
2026-04-15T03:18:10.428Z
Modified
2026-08-12T16:09:57.716919Z
Severity
  • 8.3 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
XQUIC Improper STREAM Frame Validation in Initial/Handshake Packets
Details

Improper input validation, Improper verification of cryptographic signature vulnerability in XQUIC Project XQUIC xquic on Linux (QUIC protocol implementation, packet processing module, STREAM frame handler modules) allows Protocol Manipulation.This issue affects XQUIC: through 1.8.3.

Database specific
{
    "cwe_ids": [
        "CWE-20",
        "CWE-347"
    ],
    "cna_assigner": "alibaba",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/6xxx/CVE-2026-6328.json"
}
References

Affected packages

Git / github.com/alibaba/xquic

Affected ranges

Type
GIT
Repo
https://github.com/alibaba/xquic
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
Show details
{
    "source": [
        "DESCRIPTION",
        "REFERENCES"
    ],
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "1.8.3"
        }
    ]
}

Affected versions

stable-1.*
stable-1.0.0
stable-1.0.1
v1.*
v1.1.0-beta.1
v1.1.0-beta.2
v1.1.0-stable
v1.2.0-stable
v1.3.0-beta
v1.4.0
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.2
v1.8.3
v1.9.0
v1.9.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-6328.json"
vanir_signatures
[
    {
        "signature_type": "Line",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "332206636575830313488336135022884651258",
                "125390721311552705231468860202450840040",
                "70496709984887984695956258242517344022"
            ]
        },
        "target": {
            "file": "src/transport/xqc_frame.c"
        },
        "source": "https://github.com/alibaba/xquic/commit/4764604a0e487eeb49338b4498aecda2194eae84",
        "signature_version": "v1",
        "id": "CVE-2026-6328-120c977c",
        "deprecated": false
    },
    {
        "signature_type": "Function",
        "digest": {
            "function_hash": "164270084054266829095062343711874293474",
            "length": 2337.0
        },
        "target": {
            "function": "xqc_conn_send_path_challenge",
            "file": "src/transport/xqc_conn.c"
        },
        "source": "https://github.com/alibaba/xquic/commit/994040ae7da4b0e8c754785329efad0286a74ff7",
        "signature_version": "v1",
        "id": "CVE-2026-6328-1b5cedc6",
        "deprecated": false
    },
    {
        "signature_type": "Line",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "50750606295519904077741833633600929969",
                "263881402770105293961678263567629116746",
                "136276185250294421830414333886500578580",
                "163548359958201530341781450396301979075",
                "319765355248818241322258662798619738932",
                "326092539481173590229044099306561843506",
                "83439187831266406403783256113035635298"
            ]
        },
        "target": {
            "file": "src/transport/xqc_packet_parser.c"
        },
        "source": "https://github.com/alibaba/xquic/commit/994040ae7da4b0e8c754785329efad0286a74ff7",
        "signature_version": "v1",
        "id": "CVE-2026-6328-5e5c32d5",
        "deprecated": false
    },
    {
        "signature_type": "Line",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "148872026431240894980384883080321048000",
                "171181699033522412296449299841298924505",
                "183868167876057872337389116681433765061",
                "10732616816964447794894307321813389729"
            ]
        },
        "target": {
            "file": "src/transport/xqc_send_ctl.h"
        },
        "source": "https://github.com/alibaba/xquic/commit/994040ae7da4b0e8c754785329efad0286a74ff7",
        "signature_version": "v1",
        "id": "CVE-2026-6328-64d1364a",
        "deprecated": false
    },
    {
        "signature_type": "Line",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "85635896859501040122003627024492034999",
                "262083635511637407996104029407028349247",
                "176762060474349321045714908550000679880",
                "256935870964048835881908201647840522505",
                "7691198956187540316633415863949597823",
                "209183633441136550193934349773566520033",
                "68226778162799630125950850179900630843",
                "272088445861657690468676912773323159921",
                "134317152380928198697540318101678247276",
                "68804187325661430269431852649691818121",
                "297900329069601932376053727166782474829",
                "97351260434336212845123820277964926093",
                "296639031101067366802632363305681209730",
                "128936157933126768496852763127785316123",
                "242310168248476389538097083546747853607",
                "331756364964420592886285681985156136658",
                "171015835410304252999536095241897903195",
                "216781747469656665851941002008963946577",
                "8415070932288880548360905847487924159",
                "301439052205705684279296409077176866895",
                "21784661247402294681152557043112418640",
                "15502402594705666811752119122906316144",
                "236018555112522560041892280290034653825",
                "21515157666818781226237867762226171506",
                "299082190596347549481976995936569190701"
            ]
        },
        "target": {
            "file": "src/transport/xqc_conn.c"
        },
        "source": "https://github.com/alibaba/xquic/commit/994040ae7da4b0e8c754785329efad0286a74ff7",
        "signature_version": "v1",
        "id": "CVE-2026-6328-7cc994ee",
        "deprecated": false
    },
    {
        "signature_type": "Line",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "302800498696157906437094485473860771392",
                "17546480891272246732393101613410724923",
                "80055743523724658224446174073342425399",
                "255881348701976652531320182033655063212",
                "240915324728614614098266518523548477712",
                "180801651035280835518452859331351481",
                "147252815417482834272058158991510345948",
                "172311276783258225635398220954988194363",
                "210014540126848960732663653767050714849",
                "181278238598280759914603890909816499566"
            ]
        },
        "target": {
            "file": "src/transport/xqc_send_ctl.c"
        },
        "source": "https://github.com/alibaba/xquic/commit/994040ae7da4b0e8c754785329efad0286a74ff7",
        "signature_version": "v1",
        "id": "CVE-2026-6328-8cf1cdda",
        "deprecated": false
    },
    {
        "signature_type": "Function",
        "digest": {
            "function_hash": "26937901930384364992600909254141896407",
            "length": 351.0
        },
        "target": {
            "function": "xqc_packet_decode_packet_number",
            "file": "src/transport/xqc_packet_parser.c"
        },
        "source": "https://github.com/alibaba/xquic/commit/994040ae7da4b0e8c754785329efad0286a74ff7",
        "signature_version": "v1",
        "id": "CVE-2026-6328-95c78f4b",
        "deprecated": false
    },
    {
        "signature_type": "Function",
        "digest": {
            "function_hash": "35795793281428787951321097761314646286",
            "length": 952.0
        },
        "target": {
            "function": "xqc_conn_enc_packet",
            "file": "src/transport/xqc_conn.c"
        },
        "source": "https://github.com/alibaba/xquic/commit/994040ae7da4b0e8c754785329efad0286a74ff7",
        "signature_version": "v1",
        "id": "CVE-2026-6328-9e644a79",
        "deprecated": false
    },
    {
        "signature_type": "Line",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "139789511430105364877333465798509246470",
                "41482445873398392429568676972656612173",
                "311974208164055701552510736792961849962",
                "144118394960112606999825290595909812342",
                "293012500393610354770011289420056103579",
                "79480469026522260047253447312100365764",
                "204417913205369134355360592825579616051"
            ]
        },
        "target": {
            "file": "tests/unittest/xqc_process_frame_test.c"
        },
        "source": "https://github.com/alibaba/xquic/commit/4764604a0e487eeb49338b4498aecda2194eae84",
        "signature_version": "v1",
        "id": "CVE-2026-6328-a0f3cbfe",
        "deprecated": false
    },
    {
        "signature_type": "Function",
        "digest": {
            "function_hash": "288708902266578705964584609167960673884",
            "length": 480.0
        },
        "target": {
            "function": "xqc_test_process_frame",
            "file": "tests/unittest/xqc_process_frame_test.c"
        },
        "source": "https://github.com/alibaba/xquic/commit/4764604a0e487eeb49338b4498aecda2194eae84",
        "signature_version": "v1",
        "id": "CVE-2026-6328-a2c82c6c",
        "deprecated": false
    },
    {
        "signature_type": "Line",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "235905036223444961291746567897729390068",
                "237322328265094867051207392262695663820",
                "314066912628745206459531088021067799495",
                "320731618866375677112756506275501027711"
            ]
        },
        "target": {
            "file": "include/xquic/xquic.h"
        },
        "source": "https://github.com/alibaba/xquic/commit/994040ae7da4b0e8c754785329efad0286a74ff7",
        "signature_version": "v1",
        "id": "CVE-2026-6328-c34f87a4",
        "deprecated": false
    },
    {
        "signature_type": "Function",
        "digest": {
            "function_hash": "257804467467975622754312289046032337537",
            "length": 965.0
        },
        "target": {
            "function": "xqc_enc_packet_with_pn",
            "file": "src/transport/xqc_conn.c"
        },
        "source": "https://github.com/alibaba/xquic/commit/994040ae7da4b0e8c754785329efad0286a74ff7",
        "signature_version": "v1",
        "id": "CVE-2026-6328-ebb6f8fe",
        "deprecated": false
    },
    {
        "signature_type": "Function",
        "digest": {
            "function_hash": "304202060413209124653321740827291180700",
            "length": 1361.0
        },
        "target": {
            "function": "xqc_send_packet_with_pn",
            "file": "src/transport/xqc_conn.c"
        },
        "source": "https://github.com/alibaba/xquic/commit/994040ae7da4b0e8c754785329efad0286a74ff7",
        "signature_version": "v1",
        "id": "CVE-2026-6328-ef1f78ff",
        "deprecated": false
    },
    {
        "signature_type": "Function",
        "digest": {
            "function_hash": "291021572457810130724846262742285934172",
            "length": 6381.0
        },
        "target": {
            "function": "xqc_process_stream_frame",
            "file": "src/transport/xqc_frame.c"
        },
        "source": "https://github.com/alibaba/xquic/commit/4764604a0e487eeb49338b4498aecda2194eae84",
        "signature_version": "v1",
        "id": "CVE-2026-6328-fec39928",
        "deprecated": false
    }
]
vanir_signatures_modified
"2026-08-12T16:09:57Z"