F5 Patches NGINX Vulnerability Enabling Code Execution and DoS Attacks
ID: 39dfb332-ca0b-5400-affd-ceb55124260a
STIX ID: report--39dfb332-ca0b-5400-affd-ceb55124260a
Feed Name: GBHackers
F5 published an urgent advisory describing multiple high‑severity vulnerabilities across NGINX Open Source, NGINX Plus, Gateway Fabric, Ingress Controller, and related App Protect WAF/DoS modules — most notably CVE-2026-42530 (an HTTP/3 QPACK use‑after‑free leading to repeated worker crashes and possible RCE) and CVE-2026-42055 (HTTP/2/gRPC memory‑handling flaws) — providing affected versions, fixed releases where available, and interim mitigations such as disabling HTTP/3/QUIC, restricting HTTP/2/gRPC exposure, and hardening ASLR.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
