F5 Patches Critical NGINX Vulnerabilities Enabling Unauthenticated Code Execution
ID: a298fd31-387a-5ac8-ab5e-0f89f3492a13
STIX ID: report--a298fd31-387a-5ac8-ab5e-0f89f3492a13
Feed Name: Security Affairs
F5 released emergency patches for multiple critical NGINX vulnerabilities—notably CVE-2026-42530 (a Use-After-Free in ngx_http_v3_module when HTTP/3/QUIC is enabled) and CVE-2026-42055 (a heap-based buffer overflow affecting proxy/grpc modules under specific HTTP/2 proxy and header-validation-disabled configurations). Both carry CVSS scores of 9.2 and can cause worker crashes and potentially remote code execution in environments where ASLR is disabled or bypassed; updates for NGINX Open Source, NGINX Plus, and NGINX Gateway Fabric have been issued and no exploitation in the wild has been reported.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
