Improper input validation, Improper verification of cryptographic signature vulnerability in XQUIC Project XQUIC xquic on Linux (QUIC protocol implementation, packet processing module, STREAM frame handler modules) allows Protocol Manipulation.This issue affects XQUIC: through 1.8.3.
{
"cwe_ids": [
"CWE-20",
"CWE-347"
],
"cna_assigner": "alibaba",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/6xxx/CVE-2026-6328.json"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-6328.json"
[
{
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"332206636575830313488336135022884651258",
"125390721311552705231468860202450840040",
"70496709984887984695956258242517344022"
]
},
"target": {
"file": "src/transport/xqc_frame.c"
},
"source": "https://github.com/alibaba/xquic/commit/4764604a0e487eeb49338b4498aecda2194eae84",
"signature_version": "v1",
"id": "CVE-2026-6328-120c977c",
"deprecated": false
},
{
"signature_type": "Function",
"digest": {
"function_hash": "164270084054266829095062343711874293474",
"length": 2337.0
},
"target": {
"function": "xqc_conn_send_path_challenge",
"file": "src/transport/xqc_conn.c"
},
"source": "https://github.com/alibaba/xquic/commit/994040ae7da4b0e8c754785329efad0286a74ff7",
"signature_version": "v1",
"id": "CVE-2026-6328-1b5cedc6",
"deprecated": false
},
{
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"50750606295519904077741833633600929969",
"263881402770105293961678263567629116746",
"136276185250294421830414333886500578580",
"163548359958201530341781450396301979075",
"319765355248818241322258662798619738932",
"326092539481173590229044099306561843506",
"83439187831266406403783256113035635298"
]
},
"target": {
"file": "src/transport/xqc_packet_parser.c"
},
"source": "https://github.com/alibaba/xquic/commit/994040ae7da4b0e8c754785329efad0286a74ff7",
"signature_version": "v1",
"id": "CVE-2026-6328-5e5c32d5",
"deprecated": false
},
{
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"148872026431240894980384883080321048000",
"171181699033522412296449299841298924505",
"183868167876057872337389116681433765061",
"10732616816964447794894307321813389729"
]
},
"target": {
"file": "src/transport/xqc_send_ctl.h"
},
"source": "https://github.com/alibaba/xquic/commit/994040ae7da4b0e8c754785329efad0286a74ff7",
"signature_version": "v1",
"id": "CVE-2026-6328-64d1364a",
"deprecated": false
},
{
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"85635896859501040122003627024492034999",
"262083635511637407996104029407028349247",
"176762060474349321045714908550000679880",
"256935870964048835881908201647840522505",
"7691198956187540316633415863949597823",
"209183633441136550193934349773566520033",
"68226778162799630125950850179900630843",
"272088445861657690468676912773323159921",
"134317152380928198697540318101678247276",
"68804187325661430269431852649691818121",
"297900329069601932376053727166782474829",
"97351260434336212845123820277964926093",
"296639031101067366802632363305681209730",
"128936157933126768496852763127785316123",
"242310168248476389538097083546747853607",
"331756364964420592886285681985156136658",
"171015835410304252999536095241897903195",
"216781747469656665851941002008963946577",
"8415070932288880548360905847487924159",
"301439052205705684279296409077176866895",
"21784661247402294681152557043112418640",
"15502402594705666811752119122906316144",
"236018555112522560041892280290034653825",
"21515157666818781226237867762226171506",
"299082190596347549481976995936569190701"
]
},
"target": {
"file": "src/transport/xqc_conn.c"
},
"source": "https://github.com/alibaba/xquic/commit/994040ae7da4b0e8c754785329efad0286a74ff7",
"signature_version": "v1",
"id": "CVE-2026-6328-7cc994ee",
"deprecated": false
},
{
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"302800498696157906437094485473860771392",
"17546480891272246732393101613410724923",
"80055743523724658224446174073342425399",
"255881348701976652531320182033655063212",
"240915324728614614098266518523548477712",
"180801651035280835518452859331351481",
"147252815417482834272058158991510345948",
"172311276783258225635398220954988194363",
"210014540126848960732663653767050714849",
"181278238598280759914603890909816499566"
]
},
"target": {
"file": "src/transport/xqc_send_ctl.c"
},
"source": "https://github.com/alibaba/xquic/commit/994040ae7da4b0e8c754785329efad0286a74ff7",
"signature_version": "v1",
"id": "CVE-2026-6328-8cf1cdda",
"deprecated": false
},
{
"signature_type": "Function",
"digest": {
"function_hash": "26937901930384364992600909254141896407",
"length": 351.0
},
"target": {
"function": "xqc_packet_decode_packet_number",
"file": "src/transport/xqc_packet_parser.c"
},
"source": "https://github.com/alibaba/xquic/commit/994040ae7da4b0e8c754785329efad0286a74ff7",
"signature_version": "v1",
"id": "CVE-2026-6328-95c78f4b",
"deprecated": false
},
{
"signature_type": "Function",
"digest": {
"function_hash": "35795793281428787951321097761314646286",
"length": 952.0
},
"target": {
"function": "xqc_conn_enc_packet",
"file": "src/transport/xqc_conn.c"
},
"source": "https://github.com/alibaba/xquic/commit/994040ae7da4b0e8c754785329efad0286a74ff7",
"signature_version": "v1",
"id": "CVE-2026-6328-9e644a79",
"deprecated": false
},
{
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"139789511430105364877333465798509246470",
"41482445873398392429568676972656612173",
"311974208164055701552510736792961849962",
"144118394960112606999825290595909812342",
"293012500393610354770011289420056103579",
"79480469026522260047253447312100365764",
"204417913205369134355360592825579616051"
]
},
"target": {
"file": "tests/unittest/xqc_process_frame_test.c"
},
"source": "https://github.com/alibaba/xquic/commit/4764604a0e487eeb49338b4498aecda2194eae84",
"signature_version": "v1",
"id": "CVE-2026-6328-a0f3cbfe",
"deprecated": false
},
{
"signature_type": "Function",
"digest": {
"function_hash": "288708902266578705964584609167960673884",
"length": 480.0
},
"target": {
"function": "xqc_test_process_frame",
"file": "tests/unittest/xqc_process_frame_test.c"
},
"source": "https://github.com/alibaba/xquic/commit/4764604a0e487eeb49338b4498aecda2194eae84",
"signature_version": "v1",
"id": "CVE-2026-6328-a2c82c6c",
"deprecated": false
},
{
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"235905036223444961291746567897729390068",
"237322328265094867051207392262695663820",
"314066912628745206459531088021067799495",
"320731618866375677112756506275501027711"
]
},
"target": {
"file": "include/xquic/xquic.h"
},
"source": "https://github.com/alibaba/xquic/commit/994040ae7da4b0e8c754785329efad0286a74ff7",
"signature_version": "v1",
"id": "CVE-2026-6328-c34f87a4",
"deprecated": false
},
{
"signature_type": "Function",
"digest": {
"function_hash": "257804467467975622754312289046032337537",
"length": 965.0
},
"target": {
"function": "xqc_enc_packet_with_pn",
"file": "src/transport/xqc_conn.c"
},
"source": "https://github.com/alibaba/xquic/commit/994040ae7da4b0e8c754785329efad0286a74ff7",
"signature_version": "v1",
"id": "CVE-2026-6328-ebb6f8fe",
"deprecated": false
},
{
"signature_type": "Function",
"digest": {
"function_hash": "304202060413209124653321740827291180700",
"length": 1361.0
},
"target": {
"function": "xqc_send_packet_with_pn",
"file": "src/transport/xqc_conn.c"
},
"source": "https://github.com/alibaba/xquic/commit/994040ae7da4b0e8c754785329efad0286a74ff7",
"signature_version": "v1",
"id": "CVE-2026-6328-ef1f78ff",
"deprecated": false
},
{
"signature_type": "Function",
"digest": {
"function_hash": "291021572457810130724846262742285934172",
"length": 6381.0
},
"target": {
"function": "xqc_process_stream_frame",
"file": "src/transport/xqc_frame.c"
},
"source": "https://github.com/alibaba/xquic/commit/4764604a0e487eeb49338b4498aecda2194eae84",
"signature_version": "v1",
"id": "CVE-2026-6328-fec39928",
"deprecated": false
}
]
"2026-08-12T16:09:57Z"