logo

F5 Patches NGINX Vulnerability Enabling Code Execution and DoS Attacks

ID: 39dfb332-ca0b-5400-affd-ceb55124260a

STIX ID: report--39dfb332-ca0b-5400-affd-ceb55124260a

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-06-18

Date Updated: 2026-06-18

Author: Divya

...
...

F5 published an urgent advisory describing multiple high‑severity vulnerabilities across NGINX Open Source, NGINX Plus, Gateway Fabric, Ingress Controller, and related App Protect WAF/DoS modules — most notably CVE-2026-42530 (an HTTP/3 QPACK use‑after‑free leading to repeated worker crashes and possible RCE) and CVE-2026-42055 (HTTP/2/gRPC memory‑handling flaws) — providing affected versions, fixed releases where available, and interim mitigations such as disabling HTTP/3/QUIC, restricting HTTP/2/gRPC exposure, and hardening ASLR.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.