{"id":"CVE-2026-6328","summary":"XQUIC Improper STREAM Frame Validation in Initial/Handshake Packets","details":"Improper input validation, Improper verification of cryptographic signature vulnerability in XQUIC Project XQUIC xquic on Linux (QUIC protocol implementation, packet processing module, STREAM frame handler modules) allows Protocol Manipulation.This issue affects XQUIC: through 1.8.3.","modified":"2026-08-12T16:09:57.716919Z","published":"2026-04-15T03:18:10.428Z","database_specific":{"cna_assigner":"alibaba","cwe_ids":["CWE-20","CWE-347"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/6xxx/CVE-2026-6328.json"},"references":[{"type":"WEB","url":"https://github.com"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/6xxx/CVE-2026-6328.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-6328"},{"type":"FIX","url":"https://github.com/alibaba/xquic/commit/4764604a0e487eeb49338b4498aecda2194eae84"},{"type":"PACKAGE","url":"https://github.com/alibaba/xquic"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/alibaba/xquic","events":[{"introduced":"0"},{"fixed":"994040ae7da4b0e8c754785329efad0286a74ff7"},{"fixed":"4764604a0e487eeb49338b4498aecda2194eae84"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"1.8.3"}],"source":["DESCRIPTION","REFERENCES"]}}],"versions":["v1.9.1","v1.9.0","v1.8.3","v1.8.2","v1.8.1","v1.8.0","v1.7.2","v1.7.1","v1.7.0","v1.6.3","v1.6.2","v1.6.1","v1.6.0","v1.5.0","v1.4.0","v1.3.0-beta","v1.2.0-stable","v1.1.0-stable","v1.1.0-beta.2","v1.1.0-beta.1","stable-1.0.1","stable-1.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-6328.json","vanir_signatures_modified":"2026-08-12T16:09:57Z","vanir_signatures":[{"signature_type":"Line","signature_version":"v1","source":"https://github.com/alibaba/xquic/commit/4764604a0e487eeb49338b4498aecda2194eae84","target":{"file":"src/transport/xqc_frame.c"},"deprecated":false,"digest":{"line_hashes":["332206636575830313488336135022884651258","125390721311552705231468860202450840040","70496709984887984695956258242517344022"],"threshold":0.9},"id":"CVE-2026-6328-120c977c"},{"digest":{"function_hash":"164270084054266829095062343711874293474","length":2337},"id":"CVE-2026-6328-1b5cedc6","signature_type":"Function","signature_version":"v1","source":"https://github.com/alibaba/xquic/commit/994040ae7da4b0e8c754785329efad0286a74ff7","target":{"file":"src/transport/xqc_conn.c","function":"xqc_conn_send_path_challenge"},"deprecated":false},{"signature_version":"v1","source":"https://github.com/alibaba/xquic/commit/994040ae7da4b0e8c754785329efad0286a74ff7","target":{"file":"src/transport/xqc_packet_parser.c"},"deprecated":false,"digest":{"line_hashes":["50750606295519904077741833633600929969","263881402770105293961678263567629116746","136276185250294421830414333886500578580","163548359958201530341781450396301979075","319765355248818241322258662798619738932","326092539481173590229044099306561843506","83439187831266406403783256113035635298"],"threshold":0.9},"id":"CVE-2026-6328-5e5c32d5","signature_type":"Line"},{"target":{"file":"src/transport/xqc_send_ctl.h"},"deprecated":false,"digest":{"line_hashes":["148872026431240894980384883080321048000","171181699033522412296449299841298924505","183868167876057872337389116681433765061","10732616816964447794894307321813389729"],"threshold":0.9},"id":"CVE-2026-6328-64d1364a","signature_type":"Line","signature_version":"v1","source":"https://github.com/alibaba/xquic/commit/994040ae7da4b0e8c754785329efad0286a74ff7"},{"target":{"file":"src/transport/xqc_conn.c"},"deprecated":false,"digest":{"line_hashes":["85635896859501040122003627024492034999","262083635511637407996104029407028349247","176762060474349321045714908550000679880","256935870964048835881908201647840522505","7691198956187540316633415863949597823","209183633441136550193934349773566520033","68226778162799630125950850179900630843","272088445861657690468676912773323159921","134317152380928198697540318101678247276","68804187325661430269431852649691818121","297900329069601932376053727166782474829","97351260434336212845123820277964926093","296639031101067366802632363305681209730","128936157933126768496852763127785316123","242310168248476389538097083546747853607","331756364964420592886285681985156136658","171015835410304252999536095241897903195","216781747469656665851941002008963946577","8415070932288880548360905847487924159","301439052205705684279296409077176866895","21784661247402294681152557043112418640","15502402594705666811752119122906316144","236018555112522560041892280290034653825","21515157666818781226237867762226171506","299082190596347549481976995936569190701"],"threshold":0.9},"id":"CVE-2026-6328-7cc994ee","signature_type":"Line","signature_version":"v1","source":"https://github.com/alibaba/xquic/commit/994040ae7da4b0e8c754785329efad0286a74ff7"},{"source":"https://github.com/alibaba/xquic/commit/994040ae7da4b0e8c754785329efad0286a74ff7","target":{"file":"src/transport/xqc_send_ctl.c"},"deprecated":false,"digest":{"line_hashes":["302800498696157906437094485473860771392","17546480891272246732393101613410724923","80055743523724658224446174073342425399","255881348701976652531320182033655063212","240915324728614614098266518523548477712","180801651035280835518452859331351481","147252815417482834272058158991510345948","172311276783258225635398220954988194363","210014540126848960732663653767050714849","181278238598280759914603890909816499566"],"threshold":0.9},"id":"CVE-2026-6328-8cf1cdda","signature_type":"Line","signature_version":"v1"},{"deprecated":false,"digest":{"function_hash":"26937901930384364992600909254141896407","length":351},"id":"CVE-2026-6328-95c78f4b","signature_type":"Function","signature_version":"v1","source":"https://github.com/alibaba/xquic/commit/994040ae7da4b0e8c754785329efad0286a74ff7","target":{"file":"src/transport/xqc_packet_parser.c","function":"xqc_packet_decode_packet_number"}},{"target":{"file":"src/transport/xqc_conn.c","function":"xqc_conn_enc_packet"},"deprecated":false,"digest":{"function_hash":"35795793281428787951321097761314646286","length":952},"id":"CVE-2026-6328-9e644a79","signature_type":"Function","signature_version":"v1","source":"https://github.com/alibaba/xquic/commit/994040ae7da4b0e8c754785329efad0286a74ff7"},{"deprecated":false,"digest":{"line_hashes":["139789511430105364877333465798509246470","41482445873398392429568676972656612173","311974208164055701552510736792961849962","144118394960112606999825290595909812342","293012500393610354770011289420056103579","79480469026522260047253447312100365764","204417913205369134355360592825579616051"],"threshold":0.9},"id":"CVE-2026-6328-a0f3cbfe","signature_type":"Line","signature_version":"v1","source":"https://github.com/alibaba/xquic/commit/4764604a0e487eeb49338b4498aecda2194eae84","target":{"file":"tests/unittest/xqc_process_frame_test.c"}},{"deprecated":false,"digest":{"length":480,"function_hash":"288708902266578705964584609167960673884"},"id":"CVE-2026-6328-a2c82c6c","signature_type":"Function","signature_version":"v1","source":"https://github.com/alibaba/xquic/commit/4764604a0e487eeb49338b4498aecda2194eae84","target":{"file":"tests/unittest/xqc_process_frame_test.c","function":"xqc_test_process_frame"}},{"digest":{"line_hashes":["235905036223444961291746567897729390068","237322328265094867051207392262695663820","314066912628745206459531088021067799495","320731618866375677112756506275501027711"],"threshold":0.9},"id":"CVE-2026-6328-c34f87a4","signature_type":"Line","signature_version":"v1","source":"https://github.com/alibaba/xquic/commit/994040ae7da4b0e8c754785329efad0286a74ff7","target":{"file":"include/xquic/xquic.h"},"deprecated":false},{"source":"https://github.com/alibaba/xquic/commit/994040ae7da4b0e8c754785329efad0286a74ff7","target":{"function":"xqc_enc_packet_with_pn","file":"src/transport/xqc_conn.c"},"deprecated":false,"digest":{"function_hash":"257804467467975622754312289046032337537","length":965},"id":"CVE-2026-6328-ebb6f8fe","signature_type":"Function","signature_version":"v1"},{"target":{"file":"src/transport/xqc_conn.c","function":"xqc_send_packet_with_pn"},"deprecated":false,"digest":{"function_hash":"304202060413209124653321740827291180700","length":1361},"id":"CVE-2026-6328-ef1f78ff","signature_type":"Function","signature_version":"v1","source":"https://github.com/alibaba/xquic/commit/994040ae7da4b0e8c754785329efad0286a74ff7"},{"digest":{"function_hash":"291021572457810130724846262742285934172","length":6381},"id":"CVE-2026-6328-fec39928","signature_type":"Function","signature_version":"v1","source":"https://github.com/alibaba/xquic/commit/4764604a0e487eeb49338b4498aecda2194eae84","target":{"file":"src/transport/xqc_frame.c","function":"xqc_process_stream_frame"},"deprecated":false}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N"}]}