CVE-2026-42530
published 2026-06-17CVE-2026-42530: NGINX Open Source has a vulnerability in the ngx_http_v3_module module. When NGINX Open Source is configured to use the HTTP/3 QUIC module, a remote…
PriorityP261high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
3.82%
89.4th percentile
NGINX Open Source has a vulnerability in the ngx_http_v3_module module. When NGINX Open Source is configured to use the HTTP/3 QUIC module, a remote unauthenticated attacker along with conditions beyond their control can use a specially crafted HTTP/3 session to reopen a QPACK encoder stream. This may cause a Use-after-Free in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| f5 | nginx_gateway_fabric | 1.3.0 – 1.6.2 | — |
| f5 | nginx_gateway_fabric | >= 2.0.0 < 2.6.4 | 2.6.4 |
| f5 | nginx_ingress_controller | — | — |
| f5 | nginx_ingress_controller | — | — |
| f5 | nginx_ingress_controller | 3.5.0 – 3.7.2 | — |
| f5 | nginx_ingress_controller | >= 5.0.0 < 5.5.1 | 5.5.1 |
| f5 | nginx_instance_manager | 2.17.0 – 2.22.0 | — |
| f5 | nginx_open_source | >= 1.31.0 < 1.31.2 | 1.31.2 |
| f5 | nginx_open_source | >= 1.31.0 < 1.31.2 | 1.31.2 |
Detection & IOCsextracted from sources · hover to see the quote
- →Trigger condition: NGINX must be configured to use the HTTP/3 QUIC module (listen directive includes 'quic'). Attack vector is a specially crafted HTTP/3 session that reopens a QPACK encoder stream, causing a use-after-free in the NGINX worker process. ↗
- →Monitor NGINX worker process for unexpected restarts when HTTP/3 QUIC is enabled — repeated worker restarts on a QUIC-enabled listener may indicate exploitation attempts. ↗
- →Mitigation/detection pivot: remove 'quic' from all listen directives to eliminate the attack surface. Any system still serving HTTP/3 on QUIC after patch availability should be treated as potentially exposed. ↗
- →Code execution risk is significantly elevated on systems with ASLR disabled. Prioritize detection and patching on such systems, as exploitation is more reliable there. ↗
- →Affected NGINX Plus versions: R33–R36 (fixed in R36 P6) and 37.0.0–37.0.1 (fixed in 37.0.2.1). Detect unpatched instances by version fingerprinting. ↗
- →The same QPACK encoder stream attack surface (HTTP/3 QUIC) was also abused by the unrelated XRING bug in XQUIC (Alibaba). Defenders monitoring HTTP/3 QPACK encoder stream anomalies should be aware both bug classes target this channel. ↗
- ·Vulnerability is only exploitable when NGINX is explicitly configured to use the HTTP/3 QUIC module. Default NGINX configurations without 'quic' in listen directives are NOT affected. ↗
- ·Default Red Hat Enterprise Linux security features (SELinux, ASLR, NX stack protection) significantly reduce the likelihood of achieving arbitrary code execution, downgrading practical impact on those platforms. ↗
- ·The attack requires 'conditions beyond the attacker's control' in addition to the crafted HTTP/3 session, meaning exploitation is not fully deterministic and may require specific race or state conditions in the worker process. ↗
- ·F5 did not flag this vulnerability as exploited in the wild at time of disclosure, though F5 product vulnerabilities have historically been targeted rapidly after public disclosure. ↗
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.09.2CRITICALCVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
cvelistv5v3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_redhat8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
F5
CVE-2026-42530: NGINX Open Source has a vulnerability in the ngx_http_v3_module module
vendor_f5·2026-06-17·CVSS 8.1
CVE-2026-42530 [HIGH] CWE-416 CVE-2026-42530: NGINX Open Source has a vulnerability in the ngx_http_v3_module module
CVE-2026-42530: NGINX Open Source has a vulnerability in the ngx_http_v3_module module
NGINX Open Source has a vulnerability in the ngx_http_v3_module module. When NGINX Open Source is configured to use the HTTP/3 QUIC module, a remote unauthenticated attacker along with conditions beyond their control can use a specially crafted HTTP/3 session to reopen a QPACK encoder stream. This may cause a Use-after-Free in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
F5 Advisory Articles: K000161616
F5 References: https://my.f5.com/manage/s/article/K000161616
Red Hat
nginx: ngx_http_v3_module: use-after-free issue leads to denial of service
vendor_redhat·2026-06-17·CVSS 8.1
CVE-2026-42530 [HIGH] CWE-416 nginx: ngx_http_v3_module: use-after-free issue leads to denial of service
nginx: ngx_http_v3_module: use-after-free issue leads to denial of service
NGINX Open Source has a vulnerability in the ngx_http_v3_module module. When NGINX Open Source is configured to use the HTTP/3 QUIC module, a remote unauthenticated attacker along with conditions beyond their control can use a specially crafted HTTP/3 session to reopen a QPACK encoder stream. This may cause a Use-after-Free in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
A flaw was found in the ngx_http_v3_module module of NGINX. When NGINX is configured to use the HTTP/3 QUIC
CVEList
NGINX Open-Source ngx_http_v3_module vulnerability
cvelistv5·2026-06-17·CVSS 8.1
CVE-2026-42530 [HIGH] CWE-416 NGINX Open-Source ngx_http_v3_module vulnerability
NGINX Open-Source ngx_http_v3_module vulnerability
NGINX Open Source has a vulnerability in the ngx_http_v3_module module. When NGINX Open Source is configured to use the HTTP/3 QUIC module, a remote unauthenticated attacker along with conditions beyond their control can use a specially crafted HTTP/3 session to reopen a QPACK encoder stream. This may cause a Use-after-Free in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
GHSA
NGINX Open Source has a vulnerability in the ngx_http_v3_module module.
ghsa_unreviewed·2026-06-17
CVE-2026-42530 [CRITICAL] CWE-416 NGINX Open Source has a vulnerability in the ngx_http_v3_module module.
NGINX Open Source has a vulnerability in the ngx_http_v3_module module. When NGINX Open Source is configured to use the HTTP/3 QUIC module, a remote unauthenticated attacker along with conditions beyond their control can use a specially crafted HTTP/3 session to reopen a QPACK encoder stream. This may cause a Use-after-Free in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
VulDB
F5 NGINX Open Source up to 1.31.1 QUIC use after free (K000161616)
vuldb·2026-06-17
CVE-2026-42530 [CRITICAL] F5 NGINX Open Source up to 1.31.1 QUIC use after free (K000161616)
A vulnerability has been found in F5 NGINX Open Source up to 1.31.1 and classified as critical. Impacted is an unknown function of the component QUIC Module. This manipulation causes use after free.
This vulnerability is registered as CVE-2026-42530. Remote exploitation of the attack is possible. No exploit is available.
The affected component should be upgraded.
No detection rules found.
No public exploits indexed.
Hackernews
Unpatched XRING Flaw in XQUIC Lets Remote Clients Crash HTTP/3 Servers
blogs_hackernews·2026-07-10
CVE-2026-42530 Unpatched XRING Flaw in XQUIC Lets Remote Clients Crash HTTP/3 Servers
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Unpatched XRING Flaw in XQUIC Lets Remote Clients Crash HTTP/3 Servers
A single wrong variable on one line in XQUIC, Alibaba's QUIC and HTTP/3 library, lets any remote client crash the server with a short burst of completely legal traffic. There is no patch.
FoxIO researcher Sébastien Féry disclosed the flaw on July 8 and nicknamed it XRING. He says it needs no login and no malformed packets: about 260 bytes of ordinary QPACK traffic takes the server process down.
XQUIC is open-source, so the risk is not Alibaba's alone: any server that embeds it and serves HTTP/3 with the default QPACK settings is exposed. That includes Te
Hackernews
F5 Patches Two Critical NGINX Open Source Flaws Enabling Remote Code Execution
blogs_hackernews·2026-06-18
CVE-2026-42530 F5 Patches Two Critical NGINX Open Source Flaws Enabling Remote Code Execution
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## F5 Patches Two Critical NGINX Open Source Flaws Enabling Remote Code Execution
F5 has released security updates to address two critical security flaws in NGINX Open Source that could be exploited to achieve code execution on affected systems.
The vulnerabilities are listed below -
CVE-2026-42530 (CVSS v4 score: 9.2) - A use-after-free vulnerability in the ngx_http_v3_module that could be triggered by a remote unauthenticated attacker when NGINX Open Source is configured to use the HTTP/3 QUIC module to reopen a QPACK encoder stream by means of a specially crafted HTTP/3 session, and execute code on systems with Address Spac
Bleepingcomputer
F5 issues out-of-band patches for critical NGINX vulnerabilities
blogs_bleepingcomputer·2026-06-18
CVE-2026-42530 F5 issues out-of-band patches for critical NGINX vulnerabilities
## F5 issues out-of-band patches for critical NGINX vulnerabilities
## Sergiu Gatlan
Cybersecurity company F5 has released out-of-band security updates to address multiple NGINX web server vulnerabilities, including two critical-severity flaws that could allow attackers to execute code on vulnerable systems.
The two critical vulnerabilities were found in the ngx_http_v3_module ( CVE-2026-42530 ) and the ngx_http_proxy_v2_module and ngx_http_grpc_module ( CVE-2026-42055 ), and can be exploited by unauthenticated remote attackers to trigger a denial-of-service (DoS) attack or code execution on NGINX systems with non-default configurations.
Successful exploitation causes a use-after-free or heap-based buffer overflow in the NGINX worker process, leading to a restart. In both cases, they c
Bugzilla
CVE-2026-42530 nginx: ngx_http_v3_module: use-after-free issue leads to denial of service
bugzilla·2026-06-17
CVE-2026-42530 [HIGH] CVE-2026-42530 nginx: ngx_http_v3_module: use-after-free issue leads to denial of service
CVE-2026-42530 nginx: ngx_http_v3_module: use-after-free issue leads to denial of service
NGINX Open Source has a vulnerability in the ngx_http_v3_module module. When NGINX Open Source is configured to use the HTTP/3 QUIC module, a remote unauthenticated attacker along with conditions beyond their control can use a specially crafted HTTP/3 session to reopen a QPACK encoder stream. This may cause a Use-after-Free in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
2026-06-17
Published