CVE-2026-40460
published 2026-05-13CVE-2026-40460: When NGINX Plus or NGINX Open Source are configured to use the HTTP/3 QUIC module, an attacker may be able to spoof their source IP address allowing for bypass…
PriorityP338medium6.5CVSS 3.1
AVNACLPRNUINSUCLINAL
EPSS
0.37%
29.2th percentile
When NGINX Plus or NGINX Open Source are configured to use the HTTP/3 QUIC module, an attacker may be able to spoof their source IP address allowing for bypass of authorization or bypass of rate limiting. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| f5 | dos | — | — |
| f5 | dos | 4.3.0 – 4.7.0 | — |
| f5 | nginx_gateway_fabric | 1.3.0 – 1.6.2 | — |
| f5 | nginx_gateway_fabric | 2.0.0 – 2.6.0 | — |
| f5 | nginx_ingress_controller | 3.5.0 – 3.7.2 | — |
| f5 | nginx_ingress_controller | 4.0.0 – 4.0.1 | — |
| f5 | nginx_ingress_controller | 5.0.0 – 5.4.2 | — |
| f5 | nginx_instance_manager | 2.16.0 – 2.22.0 | — |
| f5 | nginx_open_source | 1.25.0 – 1.30.0 | — |
| f5 | nginx_open_source | >= 1.26.0 < 1.30.1 | 1.30.1 |
| f5 | nginx_plus | — | — |
| f5 | nginx_plus | — | — |
| f5 | nginx_plus | >= R32 < R32 P6 | R32 P6 |
| f5 | nginx_plus | >= R36 < R36 P4 | R36 P4 |
| f5 | nginx_plus | r32 – r36 | — |
| f5 | waf | 4.9.0 – 4.16.0 | — |
| f5 | waf | 5.1.0 – 5.8.0 | — |
| f5 | waf | 5.9.0 – 5.12.1 | — |
| nginx_1.24 | nginx | — | — |
| nginx_1.26 | nginx | — | — |
| ubuntu | nginx | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
nvdv4.06.9MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_redhat6.9MEDIUM
vendor_ubuntu6.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
nginx vulnerabilities
vendor_ubuntu·2026-06-01·CVSS 6.9
CVE-2026-9256 [MEDIUM] nginx vulnerabilities
Title: nginx vulnerabilities
Summary: Several security issues were fixed in nginx.
It was discovered that nginx did not properly validate source addresses in
the HTTP/3 QUIC module. A remote attacker could possibly use this issue to
bypass authorization checks or rate limiting. This issue only affected
Ubuntu 25.04 and Ubuntu 25.10. (CVE-2026-40460)
It was discovered that nginx contained a use-after-free vulnerability in
the ngx_http_ssl_module module when client certificate verification and
OCSP validation were enabled. A remote attacker could use this issue to
cause nginx to crash, resulting in a denial of service, or possibly modify
data in memory. (CVE-2026-40701)
It was discovered that nginx did not properly handle certain proxied
responses in the ngx_http_charset_module module. A
Red Hat
nginx: NGINX: Authorization bypass via IP spoofing in HTTP/3 QUIC module
vendor_redhat·2026-05-13·CVSS 6.9
CVE-2026-40460 [MEDIUM] CWE-290 nginx: NGINX: Authorization bypass via IP spoofing in HTTP/3 QUIC module
nginx: NGINX: Authorization bypass via IP spoofing in HTTP/3 QUIC module
A flaw was found in NGINX Plus and NGINX Open Source when configured to use the HTTP/3 QUIC module. A remote attacker could exploit this by spoofing their source IP address. This vulnerability allows for the bypass of authorization controls or rate limiting mechanisms, potentially leading to unauthorized access or resource abuse.
Mitigation: To mitigate this issue, if the HTTP/3 QUIC module is not required, disable it in your NGINX configuration. This typically involves removing or commenting out the `quic` parameter from `listen` directives in your `nginx.conf` file. After modifying the configuration, a graceful reload or restart of the NGINX service is required for the changes to take effect. For example, use `sud
F5
CVE-2026-40460: When NGINX Plus or NGINX Open Source are configured to use the HTTP/3 QUIC module, an attacker may be able to spoof t...
vendor_f5·2026-05-13·CVSS 6.9
CVE-2026-40460 [MEDIUM] CWE-290 CVE-2026-40460: When NGINX Plus or NGINX Open Source are configured to use the HTTP/3 QUIC module, an attacker may be able to spoof t...
CVE-2026-40460: When NGINX Plus or NGINX Open Source are configured to use the HTTP/3 QUIC module, an attacker may be able to spoof t...
When NGINX Plus or NGINX Open Source are configured to use the HTTP/3 QUIC module, an attacker may be able to spoof their source IP address allowing for bypass of authorization or bypass of rate limiting. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected Products: NGINX Plus
F5 Advisory Articles: K000161068
F5 References: https://my.f5.com/manage/s/article/K000161068
GHSA
GHSA-h7rq-f9gq-mc8r: When NGINX Plus or NGINX Open Source are configured to use the HTTP/3 QUIC module, an attacker may be able to spoof their source IP address allowing f
ghsa_unreviewed·2026-05-13
CVE-2026-40460 [MEDIUM] CWE-290 GHSA-h7rq-f9gq-mc8r: When NGINX Plus or NGINX Open Source are configured to use the HTTP/3 QUIC module, an attacker may be able to spoof their source IP address allowing f
When NGINX Plus or NGINX Open Source are configured to use the HTTP/3 QUIC module, an attacker may be able to spoof their source IP address allowing for bypass of authorization or bypass of rate limiting. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-40460 nginx: NGINX: Authorization bypass via IP spoofing in HTTP/3 QUIC module [fedora-all]
bugzilla·2026-05-25·CVSS 6.9
CVE-2026-40460 [MEDIUM] CVE-2026-40460 nginx: NGINX: Authorization bypass via IP spoofing in HTTP/3 QUIC module [fedora-all]
CVE-2026-40460 nginx: NGINX: Authorization bypass via IP spoofing in HTTP/3 QUIC module [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
Thanks for the providing the community tracker! This is already fixed in the latest stable updates of nginx.
Bugzilla
CVE-2026-40460 nginx: NGINX: Authorization bypass via IP spoofing in HTTP/3 QUIC module
bugzilla·2026-05-13·CVSS 6.9
CVE-2026-40460 [MEDIUM] CVE-2026-40460 nginx: NGINX: Authorization bypass via IP spoofing in HTTP/3 QUIC module
CVE-2026-40460 nginx: NGINX: Authorization bypass via IP spoofing in HTTP/3 QUIC module
When NGINX Plus or NGINX Open Source are configured to use the HTTP/3 QUIC module, an attacker may be able to spoof their source IP address allowing for bypass of authorization or bypass of rate limiting. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
2026-05-13
Published