I believe that qpack(like hpack) still has some sharp edges. As in...low entropy headers are still vulnerable to leakage via a CRIME[0] style attack on the HTTP/3 header compression.
In practice, high entropy headers aren't vulnerable, as an attacker has to match the entire header:value line in order to see a difference in the compression ratio[1].
[0]: https://en.wikipedia.org/wiki/CRIME [1]: https://www.ietf.org/archive/id/draft-ietf-quic-qpack-20.htm...