Why-So-QUIC!? Racing and Fuzzing HTTP/3 WebApps using QuicDraw-UI

No ratings

Presented at BlueHat IL 2026 by

HTTP/3, the latest version of the HTTP protocol, is one of the new protocols in town. Does anyone use it? Well, more than 35% of all internet-facing websites do! HTTP/3 over QUIC, originally developed by Google, has taken security seriously, which is reflected in its RFC. In this session, we will share HTTP/3's main features and dive into its internals, then share our research journey, including some of our attack scenarios. One of HTTP/3's most promising features is its ability to solve Head-of-Line (HOL) blocking, ensuring each request has its own stream (to minimize bottlenecks between requests), leading to requests cannot block each other on the same stream. Does it mean that race conditions are impossible in HTTP/3? In the session, we will cover our journey to overcome these limitations and "Make Fuzzing and Race Conditions Work in HTTP/3". During our research, we found that the level of tooling for HTTP/3 security testing, fuzzing, and particularly race conditions testing, is lacking; therefore, we developed our own open-source tool, QuicDraw. Finally, we will demonstrate using QuicDrawUI and exploiting a 1-day race condition on a well-known identity provider hosted on a well-known cloud provider (over HTTP/3 :)) Attendees will be armed with the theory and tools required for their own HTTP/3 and QUIC research.