CVE Tools

В NGINX исправили сразу две критические RCE-уязвимости

Хакер (xakep.ru)By Мария Нефёдова

PatchNGINX Open SourceNGINX Plus

Our summary

F5 has issued out-of-band patches for two critical remote code execution issues in NGINX that can be triggered under specific conditions, potentially leading to arbitrary code execution or denial of service. The flaws are tracked as CVE-2026-42530 (use-after-free in ngx_http_v3_module, exploitable via crafted HTTP/3 QUIC sessions) and CVE-2026-42055 (heap buffer overflow affecting ngx_http_proxy_v2_module and ngx_http_grpc_module with certain proxy/grpc settings and large headers). These vulnerabilities impact NGINX Open Source and related offerings such as NGINX Plus, NGINX Gateway Fabric, NGINX Instance Manager, and NGINX Ingress Controller, and they matter because exploitation can crash and restart the NGINX worker and, without ASLR, may enable code execution.

Read at Хакер (xakep.ru)

Хакер (xakep.ru) publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store