Bochum researchers from the CASA Cluster of Excellence have discovered new vulnerabilities.

© stock.adobe.com, Oleg

IT security

Critical Vulnerabilities in QUIC Network Protocol Uncovered

Researchers from the Chair of Network and Data Security will present their work at the prestigious USENIX Security Symposium.

When we use the Internet, our data is continuously exchanged through so-called protocols. These protocols define how communication takes place and how data is transmitted securely, reliably, and efficiently. Fundamental protocols of the Internet include the Internet Protocol (IP), the Transmission Control Protocol (TCP), and Transport Layer Security (TLS). Several years ago, Google began developing the network protocol QUIC. Among other things, QUIC is designed to reduce the overhead of connection establishment and improve the efficiency of data transmission. QUIC was standardized in 2021 and has since seen increasing adoption.

QUIC-Attacker: A Testing Framework for QUIC Implementations

Security researchers at Ruhr University Bochum, Germany, have identified multiple security vulnerabilities as well as deviations from the QUIC specification in several server implementations. Using their custom-developed testing framework, QUIC-Attacker, they were able to systematically construct, modify, and transmit QUIC messages to QUIC implementations. This allowed them to investigate implementation behavior that could not be targeted systematically with existing testing tools.

The researchers from the Chair of Network and Data Security at the Faculty of Computer Science presented their work at the USENIX Security Symposium, a leading international security conference held from August 12 to 14, 2026 in Baltimore, USA. “QUIC provides extensive security mechanisms. The actual challenge, however, lies in implementing them correctly. If printed, the RFCs would span roughly 250 pages. They specify many new components and complex interactions.

"For developers, it is therefore challenging to implement all requirements completely and correctly," explains PhD researcher Nurullah Erinola, a member of the Cluster of Excellence CASA “Securing the Digital Society.” The paper similarly emphasizes that QUIC’s complexity and the interactions between packets, frames, streams, and the TLS 1.3 state machine make correct implementation particularly challenging.

Published

Wednesday
19 August 2026
9:23 am

By

Christina Scholten (CASA)

Translated by

Christina Scholten

Share