F5 Patches Two Critical NGINX Flaws in HTTP/3 and HTTP/2 Modules (CVE-2026-42530, CVE-2026-42055)
ID: 55a2498b-25a4-5428-8e37-46d409024e06
STIX ID: report--55a2498b-25a4-5428-8e37-46d409024e06
Feed Name: securityonline.info
F5 issued out-of-band patches for two critical NGINX vulnerabilities (CVSS 9.2) that can be triggered by remote, unauthenticated attackers: a use-after-free in the ngx_http_v3_module affecting HTTP/3/QUIC that can crash worker processes (and potentially allow code execution if ASLR is bypassed), and a heap-based buffer overflow in HTTP/2 proxy/gRPC paths that only triggers under specific non-default configurations. A wide range of NGINX products are affected; mitigations include upgrading to fixed builds where available, disabling HTTP/3 (remove quic) if unpatched, restoring default header settings for HTTP/2, and auditing configurations for risky options.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
