CVE-2026-6328
Last modified
CVE-2026-6328 is a high-severity vulnerability rated 8.3/10 on the CVSS scale. Improper input validation, Improper verification of cryptographic signature vulnerability in XQUIC Project XQUIC xquic on Linux (QUIC protocol implementation, packet processing module, STREAM frame handler modules) allows Protocol Manipulation.This issue affects XQUIC: through 1.8.3.. EPSS estimates a 0.20% chance of exploitation in the next 30 days.
Description
Improper input validation, Improper verification of cryptographic signature vulnerability in XQUIC Project XQUIC xquic on Linux (QUIC protocol implementation, packet processing module, STREAM frame handler modules) allows Protocol Manipulation.This issue affects XQUIC: through 1.8.3.
Metrics
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-6328?
How severe is CVE-2026-6328?
How do I fix CVE-2026-6328?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-63260Uncontrolled Resource Consumption (CWE-400) in Kibana can le…6.5
- CVE-2026-63261Uncontrolled Resource Consumption (CWE-400) in Kibana can le…6.5
- CVE-2026-63262Missing Authorization (CWE-862) in Kibana can lead to unauth…4.3
- CVE-2026-63263Uncontrolled Resource Consumption (CWE-400) in Elasticsearch…6.5
- CVE-2026-63264Joomla Extension - joomshopping.com - Reflective XSS in Joom…5.3
- CVE-2026-63265Joomla Extension - regularlabs.com - Inconsistent CSRF token…8
- CVE-2026-63280Joomla Extension - regularlabs.com - Inconsistent CSRF token…8.8
- CVE-2026-63281Joomla Extension - regularlabs.com - XSS vulnerability in Re…4.8
- CVE-2026-6329PKCS#12 MAC verification uses an attacker-controlled compari…6.5
- CVE-2026-63293A link following vulnerability in LXD allows an attacker to …9.9
- CVE-2026-63294A link following vulnerability in LXD allows an attacker to …9.9
- CVE-2026-63295An authorization bypass vulnerability in LXD allows an authe…4.3
Are you affected by CVE-2026-6328?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
