Description
When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 requests can cause NGINX worker processes to terminate.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:LExploitability: 3.9 | Impact: 1.4Attack Vector: Network
Complexity: Low
Privileges: None
User Interaction: None
Scope: Unchanged
Confidentiality: None
Integrity: None
Availability: Low
Affected Packages5 packages
Also affects: Fedora 39, 40
🔴Vulnerability Details
2OSVCVE-2024-35200: When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 requests can cause NGINX worker processes to terminate↗2024-05-29 ▶ CVEListNGINX HTTP/3 QUIC vulnerability↗2024-05-29 ▶ 📋Vendor Advisories
3F5CVE-2024-35200: When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 requests can cause NGIN...↗2024-05-29 ▶ Red Hatnginx: undisclosed HTTP/3 requests can cause NGINX worker processes to terminate↗2024-05-29 ▶ DebianCVE-2024-35200: nginx - When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undis...↗2024 ▶ 💬Community
1HackerOneCVE-2024-35200 in nginx↗2024-07-01 ▶