CVE Tools

F5 Patches Two Critical NGINX Flaws in HTTP/3 and HTTP/2 Modules (CVE-2026-42530, CVE-2026-42055)

Daily CyberSecurity (securityonline.info)By Do Son

PatchNGINX Open SourceNGINX Plus

Our summary

F5 issued urgent out-of-band fixes for two high-impact NGINX vulnerabilities, CVE-2026-42530 (HTTP/3 use-after-free) and CVE-2026-42055 (conditional HTTP/2 heap-based buffer overflow). Both can be triggered by a remote, unauthenticated attacker and carry a CVSS v4.0 score of 9.2, with issues affecting NGINX worker process stability and potential security impact depending on system hardening. This matters because the flaws target widely deployed HTTP/2/HTTP/3 and specific NGINX module paths, so even limited configuration exposure can still affect a large number of deployments.

Read at Daily CyberSecurity (securityonline.info)

Daily CyberSecurity (securityonline.info) publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store