PoC Archive PoC Archive

tag

Quic

Critical
XRING — XQUIC QPACK Ring Buffer Resize Underflow (Remote Unauthenticated DoS)
[alibaba/xquic](https://github.com/alibaba/xquic) — QUIC/HTTP-3 library, used by Tengine and reportedly across Alibaba's cloud/CDN infrastructure (Taobao, AliPay) unpatched
High
Nginx QUIC/HTTP-3 DCID Length Heap Overflow Lab (CVE-2026-0211)
CVE-2026-0211 (repository explicitly labels this as a hypothetical/simulated CVE for coursework, not a confirmed vendor-assigned vulnerability)· A custom, deliberately vulnerabilized fork of Nginx 1.25.3's QUIC transport module (ngx_event_quic_transport.c), run inside a purpose-built Docker lab — not the stock upstream Nginx release unpatched
High
HAProxy HTTP/3 (QUIC) Standalone FIN Body Validation Bypass Leading to Request Smuggling — CVE-2026-33555
CVE-2026-33555· HAProxy with HTTP/3 (QUIC) support built (USE_QUIC=1); tested on HAProxy 3.0.18 unpatched