AI description
CVE-2026-42530 is a Use-After-Free vulnerability found in the `ngx_http_v3_module` of NGINX Open Source. This flaw allows a remote, unauthenticated attacker to exploit systems configured to use the HTTP/3 QUIC module. By sending a specially crafted HTTP/3 session, an attacker can force the reopening of a QPACK encoder stream, which can lead to a Use-After-Free condition in the NGINX worker process. Successful exploitation of this vulnerability can cause the NGINX worker process to restart, resulting in a denial-of-service (DoS) condition. Additionally, attackers may be able to execute arbitrary code on systems where Address Space Layout Randomization (ASLR) is disabled or can be bypassed. The vulnerability affects NGINX Open Source versions 1.31.0 through 1.31.1, as well as specific versions of NGINX Gateway Fabric, NGINX Instance Manager, and NGINX Ingress Controller. A recommended mitigation is to disable HTTP/3 by removing "quic" from all listen directives.
- Description
- NGINX Open Source has a vulnerability in the ngx_http_v3_module module. When NGINX Open Source is configured to use the HTTP/3 QUIC module, a remote unauthenticated attacker along with conditions beyond their control can use a specially crafted HTTP/3 session to reopen a QPACK encoder stream. This may cause a Use-after-Free in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
- Source
- f5sirt@f5.com
- NVD status
- Analyzed
- Products
- nginx_gateway_fabric, nginx_ingress_controller, nginx_instance_manager, nginx_open_source
CVSS 4.0
- Type
- Secondary
- Base score
- 9.2
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- CRITICAL
CVSS 3.1
- Type
- Secondary
- Base score
- 8.1
- Impact score
- 5.9
- Exploitability score
- 2.2
- Vector string
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- HIGH
- Hype score
- Not currently trending
CVE-2026-42530: Update: the critical NGINX flaws now have a clearer technical path. CVE-2026-42530 comes down to an HTTP/3 lifetime mismatch that can leave a freed stream pointer treated as valid. CVE-2026-42055 lets oversized HPACK data write past its buffer, causing…
@lyrie_ai
14 Jul 2026
54 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
CVE-2026-42530: 🚨 Two critical NGINX flaws can lead to remote code execution. F5 has patched: • CVE-2026-42530 (HTTP/3 use-after-free) • CVE-2026-42055 (HTTP/2 heap buffer overflow) Both require specific configurations and ASLR bypass conditions. Details here →…
@lyrie_ai
12 Jul 2026
49 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
⚠️ Vulnerabilidades en productos Nginx ❗ CVE-2026-42530 ❗ CVE-2026-42055 ❗ CVE-2026-11311 ➡️ Más info: https://t.co/wyA71JN3Zw https://t.co/ne7JkzO8KV
@CERTpy
2 Jul 2026
152 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
New NGINX/QUIC RCE (CVE-2026-42530) and Cisco SD-WAN flaw (CVE-2026-20245) threaten data integrity. Encrypted DNS metadata still exposes privacy. Urgent action needed to secure data in transit. #Cybersecurity #NetworkSecurity #ZeroDay
@YourAnon_irc
24 Jun 2026
35 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CISO Daily Briefing: Splunk CVE-2026-20253 KEV remediation deadline is today; NGINX CVE-2026-42530/42055 (CVSS 9.2) and Chrome V8 CVE-2026-11645 zero-day both under active exploitation. OMB M-26-14 mandates federal logging posture change; U.S. restricts Anthropic's Fable 5/Mythos
@cloudsa
21 Jun 2026
385 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
ثغرة ذاكرة خطيرة في nginx HTTP/3 تم رصد ثغرة use after free في مُرمّز QPACK ضمن nginx HTTP/3، مسجلة باسم CVE-2026-42530. التحقق من الإصدارات وخطط التحديث أصبح أولوية. Critical memory safety iss
@fad_777
21 Jun 2026
41 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
F5、NGINXの重大な脆弱性にパッチ(CVE-2026-42530、CVE-2026-42055他) | Codebook|Security News https://t.co/nmKvmbVxBs
@ohhara_shiojiri
20 Jun 2026
68 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Use-after-free in the QPACK encoder of nginx HTTP/3 - CVE-2026-42530 https://t.co/EsayGiNb9b
@Dinosn
20 Jun 2026
1619 Impressions
1 Retweet
12 Likes
5 Bookmarks
0 Replies
0 Quotes
NGINXのHTTP/3モジュールとHTTP/2プロキシ・gRPCモジュールに、未認証でリモートから悪用可能なCritical脆弱性2件(CVE-2026-42530、CVE-2026-42055)が見つかり、定例外の緊急パッチが公開されています。CVSS-v4.0で9.2と評価
@MalwareBibleJP
20 Jun 2026
1637 Impressions
2 Retweets
16 Likes
6 Bookmarks
0 Replies
0 Quotes
CVE-2026-42530 & CVE-2026-42055: F5 Patches NGINX Vulnerabilities https://t.co/JiQyUTUIEh CVE-2026-42530 & CVE-2026-42055: F5 Patches NGINX Vulnerabilities Introduction to Malware Binary Triage (IMBT) Course Looking to level up your skills? Get 10% off using coupon cod
@f1tym1
19 Jun 2026
48 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
CVE-2026-42530 & CVE-2026-42055: F5 Patches NGINX Vulnerabilities https://t.co/t5Bh3XdVSv CVE-2026-42530 & CVE-2026-42055: F5 Patches NGINX Vulnerabilities F5 has released out-of-band security updates for two NGINX vulnerabilities that can affect exposed web infrastruct
@f1tym1
19 Jun 2026
34 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 Upozorňujeme na závažné zranitelnosti v NGINX, CVE-2026-42530 a CVE-2026-42055. CVE-2026-42530: jedná se o chybu typu use-after-free v modulu ngx_http_v3_module, která může být zneužita vzdáleným neautentizovaným útočníkem při použití HTTP/3 QUIC a speci
@GOVCERT_CZ
19 Jun 2026
378 Impressions
2 Retweets
4 Likes
1 Bookmark
0 Replies
0 Quotes
CVE Alert: Critical NGINX Open Source Flaws F5 has released security updates for two critical NGINX Open Source vulnerabilities that could allow remote code execution on affected systems. • CVE-2026-42530 | CVSS 9.2 • CVE-2026-42055 | CVSS 9.2 The flaws impact certain NGIN
@CloneSystemsInc
19 Jun 2026
49 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
NGINX admins, your weekend might be starting early (and not in a good way). 🚨 F5 just dropped out-of-band fixes for two nasty NGINX flaws that can trigger remote DoS and potentially lead to RCE. 🔹 CVE-2026-42530 (HTTP/3 QUIC) 🔹 CVE-2026-42055 (HTTP/2 & gRPC proxyin
@socradar
19 Jun 2026
128 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
Warning: #F5 released updates for vulns in #NGINX Open Source & #NGINX Gateway Fabric, incl CVE-2026-42530, CVE-2026-42055, CVE-2026-11311, and CVE-2026-50107. Exploitation could lead to DoS, arbitrary code execution, or NGINX configuration injection. #Patch #Patch #Patch.
@CCBalert
19 Jun 2026
169 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Breaking: Two critical NGINX bugs just dropped. CVE-2026-42530: HTTP/3 QPACK UAF CVE-2026-42055: HTTP/2/gRPC heap overflow Remote. Unauthenticated. CVSS 9.2. Patches are live. Patch em before the exploit race starts: https://t.co/VIh2e3oh65
@thecybersecguru
19 Jun 2026
94 Impressions
1 Retweet
1 Like
1 Bookmark
0 Replies
0 Quotes
⚠️F5、NGINXの重大な脆弱性にパッチ(CVE-2026-42530、CVE-2026-42055他) 🇮🇳インド政府、入試問題流出について供述書を提出 当該チャンネルの監視は困難とTelegramが認めたと主張 〜サイバーアラート6月19日〜 h
@MachinaRecord
19 Jun 2026
180 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
Two critical NGINX vulnerabilities, CVE-2026-42530 and CVE-2026-42055, let remote attackers crash workers and possibly run code. Patch NGINX now. #NGINX #F5 #HTTP3 #BufferOverflow #CVE #Vulnerability https://t.co/Id0N4uD8Ky https://t.co/iqSsJs0E0b
@Daily_CyberSec
19 Jun 2026
242 Impressions
0 Retweets
2 Likes
0 Bookmarks
0 Replies
0 Quotes
🔒 #CyberSecurity CVE-2026-42530: NGINX Open Source HTTP/3 RCE — Detection and Remediation "F5 patches CVE-2026-42530 (CVSS 9.2), a critical unauthenticated RCE flaw in NGINX HTTP/3." 🔗 https://t.co/fjYbr3lb3c #CyberSecurity #ThreatIntel #cve #zeroday #patchtuesday
@SecurityAr58409
19 Jun 2026
73 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
TRC analysis shows attackers exploiting critical NGINX vulnerabilities CVE-2026-42530 and CVE-2026-42055 can achieve initial compromise and move laterally across networks. Runtime segmentation helps contain post-compromise activity after web server exploitation. #ZeroDay
@aviatrixtrc
19 Jun 2026
69 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
F5 patched two critical NGINX Open Source flaws, CVE-2026-42530 and CVE-2026-42055, that could enable remote code execution in certain configs. Mitigations include disabling HTTP/3 or adjusting headers. #NGINX #F5 #CVE202642530 https://t.co/mCjAEP4eC1
@TweetThreatNews
18 Jun 2026
135 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
F5 has released patches for two critical vulnerabilities in NGINX Open Source, CVE-2026-42530 and CVE-2026-42055, both with a CVSS v4 score of 9.2. These flaws could allow remote code execution on affected systems. Administrators are urged to apply the updates promptly to secure
@dailytechonx
18 Jun 2026
70 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 Two critical NGINX flaws can lead to remote code execution. F5 has patched: • CVE-2026-42530 (HTTP/3 use-after-free) • CVE-2026-42055 (HTTP/2 heap buffer overflow) Both require specific configurations and ASLR bypass conditions. Details here → https://t.co/x1251rhB3
@TheHackersNews
18 Jun 2026
22713 Impressions
56 Retweets
165 Likes
58 Bookmarks
3 Replies
5 Quotes
قابل توجه ادمین های وب سرور Nginx : برای وب سرور Nginx ، دو آسیب پذیری با کدهای شناسایی CVE-2026-42530 و CVE-2026-42055 منتشر شده است . این آسیب پذیری ها از نوع RCE و DOS می باشند ک
@EthicalSafe
18 Jun 2026
12 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
F5 Patches Critical NGINX Vulnerabilities Enabling Unauthenticated Code Execution: F5 released emergency updates for critical NGINX flaws (CVE-2026-42530, CVE-2026-42055) that could enable unauthenticated code execution. F5 has issued out-of-band patches… https://t.co/Egh8TpmJV
@shah_sheikh
18 Jun 2026
50 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 Edge patch watch: F5 released out-of-band updates for NGINX flaws including CVE-2026-42530 and CVE-2026-42055. SecurityWeek says unauthenticated remote attackers can trigger DoS, with code execution possible in some conditions. #NGINX #Cyber https://t.co/6blR5xlopn
@Divinmentis
18 Jun 2026
76 Impressions
0 Retweets
0 Likes
0 Bookmarks
2 Replies
0 Quotes
NGINXなどF5製品群で複数の脆弱性。 High CVEsは以下4件 CVE-2026-42530 CVE-2026-42055 CVE-2026-11311 CVE-2026-50107 K000161614: Out-of-band Security Notification (June 17, 2026) https://t.co/cu9fv9gL8u
@autumn_good_35
18 Jun 2026
432 Impressions
1 Retweet
1 Like
0 Bookmarks
0 Replies
0 Quotes
🚨 Nginx 1.31.2 yayınlandı. Öne çıkan yamalar: • HTTP/3 + QUIC tarafında use-after-free açığı (CVE-2026-42530) • HTTP/2/gRPC proxy senaryolarında heap overflow riski (CVE-2026-42055) • charset_map UTF-8 işleme kaynaklı memory overread (CVE-2026-48142) Mutl
@ridvanyagli
18 Jun 2026
151 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
1 Quote
NGINX CVE-2026-42530 & CVE-2026-42055: F5 Critical Patches F5 released out-of-band patches on June 18, 2026 for four NGINX flaws, including two CVSS… Read more: https://t.co/0exuxzle00 #Nginx #F5 #Cve #RemoteCodeExecution
@navanem
18 Jun 2026
0 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 F5 issues emergency patches for two critical NGINX vulnerabilities that could let unauthenticated attackers crash servers or execute code 🔹 CVE-2026-42530 & CVE-2026-42055 affect NGINX Plus, Open Source, Gateway Fabric & Instance Manager 🔹 No active exploitati
@techepages
18 Jun 2026
53 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
2026-06-17 nginx-1.30.3 stable and nginx-1.31.2 mainline versions have been released, (CVE-2026-42530),(CVE-2026-48142),(CVE-2026-42055), fix https://t.co/7HtZYwRWiH
@hacker_infra
17 Jun 2026
45 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
nginx 1.30.3 and 1.31.2 released to fix CVE-2026-42055, CVE-2026-48142 and CVE-2026-42530 https://t.co/8dCg0h930B
@jedisct1
17 Jun 2026
681 Impressions
2 Retweets
10 Likes
0 Bookmarks
0 Replies
1 Quote
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:f5:nginx_gateway_fabric:*:*:*:*:*:*:*:*",
"matchCriteriaId": "15B7F1FD-0C49-460F-9CB8-23DA730EC4BE",
"versionEndIncluding": "1.6.2",
"versionStartIncluding": "1.3.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:f5:nginx_gateway_fabric:*:*:*:*:*:*:*:*",
"matchCriteriaId": "8495C4C7-3BFA-49CD-B527-7E1EE9827634",
"versionEndExcluding": "2.6.4",
"versionStartIncluding": "2.0.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:f5:nginx_ingress_controller:*:*:*:*:*:*:*:*",
"matchCriteriaId": "10D5B143-4C1E-4626-8B49-3EA7160E9256",
"versionEndIncluding": "3.7.2",
"versionStartIncluding": "3.5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:f5:nginx_ingress_controller:*:*:*:*:*:*:*:*",
"matchCriteriaId": "965E7D6E-288B-438E-A2A8-A25802E34933",
"versionEndExcluding": "5.5.1",
"versionStartIncluding": "5.0.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:f5:nginx_ingress_controller:4.0.0:*:*:*:*:*:*:*",
"matchCriteriaId": "896F495E-50C2-4A10-8FE8-F4D0AD52F6FF",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:f5:nginx_ingress_controller:4.0.1:*:*:*:*:*:*:*",
"matchCriteriaId": "0ACDA17B-D0AB-46C1-9D58-21DF6ED5479E",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:f5:nginx_instance_manager:*:*:*:*:*:*:*:*",
"matchCriteriaId": "BCFCE3FC-61E0-4749-8F09-EEB4B09B1218",
"versionEndIncluding": "2.22.0",
"versionStartIncluding": "2.17.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:f5:nginx_open_source:*:*:*:*:*:*:*:*",
"matchCriteriaId": "2C3B90C4-D305-4F5F-B4B2-CD09918D1C94",
"versionEndExcluding": "1.31.2",
"versionStartIncluding": "1.31.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]