9.2

CVE-2026-42055

Medienbericht

NGINX ngx_http_proxy_v2_module and ngx_http_grpc_module vulnerability

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass directives are used to proxy HTTP/2 traffic, the ignore_invalid_headers directive is set to off, and the large_client_header_buffers directive size is larger than 2 megabytes. A remote, unauthenticated attacker, along with conditions beyond their control, could send large headers while creating an upstream request. This may cause a heap-based buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. 


Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
F5 ≫ Dos SwPlatform nginx Version >= 4.3.0 <= 4.7.0
F5 ≫ Dos Version 4.9.0 SwPlatform nginx
F5 ≫ Nginx Gateway Fabric Version >= 1.3.0 <= 1.6.2
F5 ≫ Nginx Gateway Fabric Version >= 2.0.0 <= 2.6.3
F5 ≫ Nginx Ingress Controller SwEdition continuous_releases Version >= 3.5.0 <= 3.7.2
F5 ≫ Nginx Ingress Controller SwEdition continuous_releases Version >= 4.0.0 <= 4.0.1
F5 ≫ Nginx Ingress Controller SwEdition continuous_releases Version >= 5.0.0 <= 5.5.0
F5 ≫ Nginx Instance Manager Version >= 2.17.0 <= 2.22.0
F5 ≫ Nginx Open Source Version >= 1.0.0 <= 1.30.2
F5 ≫ Nginx Open Source Version >= 1.31.0 <= 1.31.1
F5 ≫ Nginx Plus SwEdition long-term_support Version >= 37.0.0.1 < 37.0.2.1
F5 ≫ Nginx Plus SwEdition continuous_releases Version >= r33 < r36
F5 ≫ Nginx Plus Version r36 Update - SwEdition continuous_releases
F5 ≫ Nginx Plus Version r36 Update p1 SwEdition continuous_releases
F5 ≫ Nginx Plus Version r36 Update p2 SwEdition continuous_releases
F5 ≫ Nginx Plus Version r36 Update p3 SwEdition continuous_releases
F5 ≫ Nginx Plus Version r36 Update p4 SwEdition continuous_releases
F5 ≫ Nginx Plus Version r36 Update p5 SwEdition continuous_releases
F5 ≫ Waf SwPlatform nginx Version >= 4.10.0 <= 4.16.0
F5 ≫ Waf SwPlatform nginx Version >= 5.2.0 <= 5.8.0
F5 ≫ Waf SwPlatform nginx Version >= 5.9.0 <= 5.13.1
Redhat ≫ Discovery Version -
Redhat ≫ Hardened Images Version -
Redhat ≫ Update Infrastructure Version >= 5.0 < 5.2
Redhat ≫ Enterprise Linux Version 8.0
Redhat ≫ Enterprise Linux Version 9.0
Redhat ≫ Enterprise Linux Version 10.0
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 4.02% 0.896
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
F5 9.2 0 0
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
F5 8.1 2.2 5.9
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
0b0ca135-0b70-47e7-9f44-1890c2a1c46c 8.1 2.2 5.9
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-122 Heap-based Buffer Overflow

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

CWE-131 Incorrect Calculation of Buffer Size

The product does not correctly calculate the size to be used when allocating a buffer, which could lead to a buffer overflow.

CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
22.06.2026 16:32
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
18.06.2026 20:51
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
18.06.2026 13:51
https://bugzilla.redhat.com/show_bug.cgi?id=2489866
Third Party Advisory
Issue Tracking
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42055.json
Third Party Advisory
https://my.f5.com/manage/s/article/K000161584
Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:27197
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:36331
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:36364
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:36618
Third Party Advisory
https://access.redhat.com/security/cve/CVE-2026-42055
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:36639
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:38847
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:44481
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:46836
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:58981