PT-2026-50439 · F5+1 · Nginx Open Source+1

CVE-2026-42530

·

Published

2026-06-17

·

Updated

2026-08-13

CVSS v4.0

9.2

Critical

VectorAV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions NGINX Open Source versions 1.31.0 through 1.31.1 NGINX Ingress Controller (affected versions not specified) NGINX Gateway Fabric (affected versions not specified) NGINX Instance Manager (affected versions not specified)
Description A use-after-free issue exists in the ngx http v3 module module. When the software is configured to use the HTTP/3 QUIC module, a remote unauthenticated attacker can use a specially crafted HTTP/3 session to reopen a QPACK encoder stream. This can lead to a crash of the NGINX worker process, resulting in a denial of service. Furthermore, it may allow for arbitrary code execution on systems where Address Space Layout Randomization (ASLR)—a security technique that randomly arranges the address space positions of key data areas of a process—is disabled or bypassed.
Recommendations Update NGINX Open Source to version 1.31.2 or later. At the moment, there is no information about a newer version that contains a fix for this vulnerability for NGINX Ingress Controller, NGINX Gateway Fabric, and NGINX Instance Manager.

Exploit

Fix

RCE

DoS

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-08509
BIT-NGINX-2026-42530
BIT-NGINX-GATEWAY-2026-42530
CVE-2026-42530
OPENSUSE-SU-2026:11066-1

Affected Products

Nginx Open Source
Nginx