Ruhr-Uni-Bochum
HGI

Copyright: HGI, stock.adobe.com: chinnarach

Security Researchers Uncover Critical Vulnerabilities in QUIC Implementations

Researchers from the Chair of Network and Data Security presented their work at the prestigious USENIX Security Symposium 2026.

Copyright: Adobe/ Ilja

When we use the Internet, our data is continuously exchanged through so-called protocols. These protocols define how communication takes place and how data is transmitted securely, reliably, and efficiently. Fundamental protocols of the Internet include the Internet Protocol (IP), the Transmission Control Protocol (TCP), and Transport Layer Security (TLS). Several years ago, Google began developing the network protocol QUIC. Among other things, QUIC is designed to reduce the overhead of connection establishment and improve the efficiency of data transmission. QUIC was standardized in 2021 and has since seen increasing adoption.

QUIC-Attacker: A Testing Framework for QUIC Implementations

Security researchers at Ruhr University Bochum have identified multiple security vulnerabilities as well as deviations from the QUIC specification in several server implementations. Using their custom-developed testing tool QUIC-Attacker, the researchers were able to systematically construct, modify, and send protocol messages to QUIC implementations. This allowed them to investigate behaviors that could not be specifically tested with existing testing tools.

The researchers from the Chair of Network and Data Security at the Faculty of Computer Science and the Horst Goertz Institute for IT Security at Ruhr University Bochum presented their work at the USENIX Security Symposium, a leading international security conference held from August 12 to 14 in Baltimore, USA. “QUIC provides extensive security mechanisms. The actual challenge, however, lies in implementing them correctly. If printed, the RFCs would span roughly 250 pages. They specify many new components and complex interactions. For developers, it is therefore challenging to implement all requirements completely and correctly,” explains PhD researcher Nurullah Erinola, a member of the Cluster of Excellence CASA “Securing the Digital Society.” The paper similarly emphasizes that QUIC’s complexity and the interactions between packets, frames, streams, and the TLS 1.3 state machine make correct implementation particularly challenging.

Eight Denial-of-Service Vulnerabilities and Two Injection Vulnerabilities

As part of their study, the research team analyzed 15 different open-source QUIC server implementations. These included implementations developed by major companies, such as Alibaba’s XQUIC. The results revealed significant differences among the implementations under investigation. Overall, the researchers identified eight denial-of-service (DoS) vulnerabilities caused by specially crafted combinations of QUIC messages that can trigger server crashes. In addition, they discovered two injection vulnerabilities in which an attacker can inject messages into the protocol flow during connection establishment between a client and a server. One of the two injection vulnerabilities in Alibaba’s XQUIC was particularly severe. The implementation failed to fully enforce certain checks mandated by the QUIC specification. As a result, an attacker could inject application data during connection establishment between a client and a server. The vulnerability was assigned (CVSS 8,3/10), a unique identifier in the standardized database of publicly known security vulnerabilities. The vulnerability is classified as high severity, with a CVSS score of 8.3 out of 10.

QUIC-Attacker Available as an Open-Source Tool

All identified issues were responsibly disclosed to the affected development teams. “We received positive feedback from industry. The teams responsible were grateful that we helped them make their implementations more secure,” says Erinola. To contribute to the long-term security of QUIC implementations, the research team has made QUIC-Attacker available as an open source testing framework. The framework enables developers to systematically test their QUIC implementations for correct behavior, specification compliance, and potential security vulnerabilities. It also provides a foundation that other research teams can build upon.

The work builds on previous successes of the Chair of Network and Data Security, headed by CASA Principal Investigator Prof. Dr. Jörg Schwenk. The TLS-Attacker framework, also developed at the chair, is an open-source tool for the flexible analysis of TLS implementations. It has been used in research and practice for many years, is widely used in the international security research community, and has received substantial recognition worldwide.

Paper: "Breaking the Boundaries: Analyzing QUIC Frame-Packet Interactions With QUIC-Attacker". Nurullah Erinola, Marcel Maehren, Marcus Brinkmann, and Jörg Schwenk, Ruhr University Bochum

General note: In case of using gender-assigning attributes we include all those who consider themselves in this gender regardless of their own biological sex.