Ruhr-Uni-Bochum

Breaking the Boundaries: Analyzing QUIC Frame-Packet Interactions With QUIC-Attacker

2026

Konferenz / Journal

Research Hub

Hub 3: Trustworthy Systems

Abstract

QUIC is a new network protocol based on UDP that replaces TCP and TLS with an integrated protocol. It provides multiplexing of streams over a single encrypted and authenticated connection. The QUIC standard allows many different combinations of UDP datagrams, and QUIC packets, frames, and streams to transport the same information. This implies that testing the receiving side of QUIC is difficult.

We develop probes to explore how different QUIC server implementations handle the coalescence and fragmentation of payloads, covering both valid and invalid combinations of datagrams, packets, and frames. Already at this basic level, we observe significant differences between implementations, some of which pointing towards exploitable vulnerabilities. Previous QUIC research tools were not designed to implement such probes. To address this limitation, we present QUIC-Attacker, a testing framework that allows maximum freedom on the sending side of QUIC.

We present our results on these probes when applied to 15 QUIC server libraries, uncovering eight DoS vulnerabilities caused by unhandled exceptions and exploitable injection vulnerabilities in Kwik and Alibaba's XQUIC.

Tags

Network Security
Software Security