9.2

CVE-2026-42530

Medienbericht

NGINX Open-Source ngx_http_v3_module vulnerability

NGINX Open Source has a vulnerability in the ngx_http_v3_module module. When NGINX Open Source is configured to use the HTTP/3 QUIC module, a remote unauthenticated attacker along with conditions beyond their control can use a specially crafted HTTP/3 session to reopen a QPACK encoder stream. This may cause a Use-after-Free in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR.  


Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
F5Nginx Gateway Fabric Version >= 1.3.0 <= 1.6.2
F5Nginx Gateway Fabric Version >= 2.0.0 < 2.6.4
F5Nginx Ingress Controller Version >= 3.5.0 <= 3.7.2
F5Nginx Ingress Controller Version >= 5.0.0 < 5.5.1
F5Nginx Ingress Controller Version4.0.0
F5Nginx Ingress Controller Version4.0.1
F5Nginx Instance Manager Version >= 2.17.0 <= 2.22.0
F5Nginx Open Source Version >= 1.31.0 < 1.31.2
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.68% 0.885
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
F5 9.2 0 0
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
F5 8.1 2.2 5.9
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
0b0ca135-0b70-47e7-9f44-1890c2a1c46c 8.1 2.2 5.9
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-416 Use After Free

The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
10.07.2026 14:07
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
22.06.2026 16:32
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
18.06.2026 20:51
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
18.06.2026 13:51
https://bugzilla.redhat.com/show_bug.cgi?id=2489872
Third Party Advisory
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42530.json
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:20351
https://my.f5.com/manage/s/article/K000161616
Vendor Advisory
https://access.redhat.com/security/cve/CVE-2026-42530
Third Party Advisory