cbcvebase.
CVE-2026-42530
published 2026-06-17

CVE-2026-42530: NGINX Open Source has a vulnerability in the ngx_http_v3_module module. When NGINX Open Source is configured to use the HTTP/3 QUIC module, a remote…

PriorityP261high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
3.82%
89.4th percentile
NGINX Open Source has a vulnerability in the ngx_http_v3_module module. When NGINX Open Source is configured to use the HTTP/3 QUIC module, a remote unauthenticated attacker along with conditions beyond their control can use a specially crafted HTTP/3 session to reopen a QPACK encoder stream. This may cause a Use-after-Free in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected

9 ranges
VendorProductVersion rangeFixed in
f5nginx_gateway_fabric1.3.0 – 1.6.2
f5nginx_gateway_fabric>= 2.0.0 < 2.6.42.6.4
f5nginx_ingress_controller
f5nginx_ingress_controller
f5nginx_ingress_controller3.5.0 – 3.7.2
f5nginx_ingress_controller>= 5.0.0 < 5.5.15.5.1
f5nginx_instance_manager2.17.0 – 2.22.0
f5nginx_open_source>= 1.31.0 < 1.31.21.31.2
f5nginx_open_source>= 1.31.0 < 1.31.21.31.2

Detection & IOCsextracted from sources · hover to see the quote

  • Trigger condition: NGINX must be configured to use the HTTP/3 QUIC module (listen directive includes 'quic'). Attack vector is a specially crafted HTTP/3 session that reopens a QPACK encoder stream, causing a use-after-free in the NGINX worker process.
  • Monitor NGINX worker process for unexpected restarts when HTTP/3 QUIC is enabled — repeated worker restarts on a QUIC-enabled listener may indicate exploitation attempts.
  • Mitigation/detection pivot: remove 'quic' from all listen directives to eliminate the attack surface. Any system still serving HTTP/3 on QUIC after patch availability should be treated as potentially exposed.
  • Code execution risk is significantly elevated on systems with ASLR disabled. Prioritize detection and patching on such systems, as exploitation is more reliable there.
  • Affected NGINX Plus versions: R33–R36 (fixed in R36 P6) and 37.0.0–37.0.1 (fixed in 37.0.2.1). Detect unpatched instances by version fingerprinting.
  • The same QPACK encoder stream attack surface (HTTP/3 QUIC) was also abused by the unrelated XRING bug in XQUIC (Alibaba). Defenders monitoring HTTP/3 QPACK encoder stream anomalies should be aware both bug classes target this channel.
  • ·Vulnerability is only exploitable when NGINX is explicitly configured to use the HTTP/3 QUIC module. Default NGINX configurations without 'quic' in listen directives are NOT affected.
  • ·Default Red Hat Enterprise Linux security features (SELinux, ASLR, NX stack protection) significantly reduce the likelihood of achieving arbitrary code execution, downgrading practical impact on those platforms.
  • ·The attack requires 'conditions beyond the attacker's control' in addition to the crafted HTTP/3 session, meaning exploitation is not fully deterministic and may require specific race or state conditions in the worker process.
  • ·F5 did not flag this vulnerability as exploited in the wild at time of disclosure, though F5 product vulnerabilities have historically been targeted rapidly after public disclosure.

CVSS provenance

nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.09.2CRITICALCVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
cvelistv5v3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_redhat8.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.