PT-2026-50439 · F5+1 · Nginx Open Source+1
CVE-2026-42530
·
Published
2026-06-17
·
Updated
2026-08-13
CVSS v4.0
9.2
Critical
| Vector | AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
NGINX Open Source versions 1.31.0 through 1.31.1
NGINX Ingress Controller (affected versions not specified)
NGINX Gateway Fabric (affected versions not specified)
NGINX Instance Manager (affected versions not specified)
Description
A use-after-free issue exists in the
ngx http v3 module module. When the software is configured to use the HTTP/3 QUIC module, a remote unauthenticated attacker can use a specially crafted HTTP/3 session to reopen a QPACK encoder stream. This can lead to a crash of the NGINX worker process, resulting in a denial of service. Furthermore, it may allow for arbitrary code execution on systems where Address Space Layout Randomization (ASLR)—a security technique that randomly arranges the address space positions of key data areas of a process—is disabled or bypassed.Recommendations
Update NGINX Open Source to version 1.31.2 or later.
At the moment, there is no information about a newer version that contains a fix for this vulnerability for NGINX Ingress Controller, NGINX Gateway Fabric, and NGINX Instance Manager.
Exploit
Fix
RCE
DoS
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nginx Open Source
Nginx