PT-2026-50438 · F5+5 · Nginx Plus+6
CVE-2026-42055
·
Published
2026-06-17
·
Updated
2026-08-11
CVSS v4.0
9.2
Critical
| Vector | AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
NGINX Plus (affected versions not specified)
NGINX Open Source (affected versions not specified)
Description
A flaw in the
ngx http proxy v2 module and ngx http grpc module modules can be triggered when NGINX is configured to proxy HTTP/2 traffic using the proxy http version set to 2 or the grpc pass directives, while the ignore invalid headers directive is set to off and the large client header buffers directive is larger than 2 megabytes. A remote, unauthenticated attacker can send specially crafted large headers during an upstream request, causing a heap-based buffer overflow in the NGINX worker process. This can lead to a Denial of Service (DoS) via a process restart or potentially allow arbitrary code execution on systems where Address Space Layout Randomization (ASLR)—a security technique that randomizes memory addresses to prevent exploitation—is disabled or bypassed.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
As a temporary workaround, set the
ignore invalid headers directive to on or ensure the large client header buffers directive is set to 2 megabytes or less.DoS
Heap Based Buffer Overflow
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linuxmint
Nginx Open Source
Nginx Plus
Nginx
Red Os
Rocky Linux
Ubuntu