NGINX web server critical flaws (multiple vulnerabilities)
Vulnerability
Summary
Hide ▲
Show ▼
NGINX had two critical web server vulnerabilities, CVE-2026-42530 and CVE-2026-42055, that can let remote unauthenticated attackers trigger remote code execution on affected deployments. The flaws affect ngx_http_v3_module, ngx_http_proxy_v2_module, and ngx_http_grpc_module in NGINX Open Source and related F5 products, especially when HTTP/3 QUIC or specific HTTP/2 proxy settings are enabled. F5 released security updates, with fixes including 1.31.2, 1.30.3, 2.6.4, 37.0.2.1, and R36 P6, and advised temporary mitigations such as disabling HTTP/3 or removing ignore_invalid_headers off and reducing large_client_header_buffers below 2 MB.
Related Happenings
XQUIC XRING remote crash security flaw
Vulnerability
H score1
First: 10.07.2026 14:47
Last: 10.07.2026 14:47
Sources 1
About this happening:
XQUIC's XRING flaw leaves HTTP/3 servers exposed to remote crashes through valid QPACK traffic, with no patch available. The bug needs no login and no malforme...
XQUIC XRING remote crash security flaw
VulnerabilityAbout this happening: XQUIC's XRING flaw leaves HTTP/3 servers exposed to remote crashes through valid QPACK traffic, with no patch available. The bug needs no login and no malforme...
NGINX and Apache HTTPD HTTP/2 Bomb mitigations
Advisory/Mitigation
H score46
First: 03.06.2026 11:33
Last: 03.06.2026 11:33
Sources 1
About this happening:
Calif issued mitigation guidance for NGINX and Apache HTTPD operators after HTTP/2 Bomb was found to enable a remote denial-of-service against default HTTP/2 confi...
NGINX and Apache HTTPD HTTP/2 Bomb mitigations
Advisory/MitigationAbout this happening: Calif issued mitigation guidance for NGINX and Apache HTTPD operators after HTTP/2 Bomb was found to enable a remote denial-of-service against default HTTP/2 confi...
OpenDCIM multi-flaw exploitation wave (CVE-2026-28515, CVE-2026-28516, CVE-2026-28517)
Exploitation Wave
H score46
First: 17.05.2026 14:57
Last: 17.05.2026 14:57
Sources 1
About this happening:
openDCIM is seeing an active exploitation wave tied to CVE-2026-28515, CVE-2026-28516, and CVE-2026-28517, with attackers targeting vulnerable installations an...
OpenDCIM multi-flaw exploitation wave (CVE-2026-28515, CVE-2026-28516, CVE-2026-28517)
Exploitation WaveAbout this happening: openDCIM is seeing an active exploitation wave tied to CVE-2026-28515, CVE-2026-28516, and CVE-2026-28517, with attackers targeting vulnerable installations an...
NGINX rewrite-rule workaround for CVE-2026-42945
Advisory/Mitigation
H score23
First: 14.05.2026 18:43
Last: 14.05.2026 18:43
Sources 1
About this happening:
F5 issued a workaround for vulnerable NGINX rewrite rules, reducing exposure to CVE-2026-42945 for operators who cannot upgrade immediately. The guidance replaces...
NGINX rewrite-rule workaround for CVE-2026-42945
Advisory/MitigationAbout this happening: F5 issued a workaround for vulnerable NGINX rewrite rules, reducing exposure to CVE-2026-42945 for operators who cannot upgrade immediately. The guidance replaces...
NGINX Plus and NGINX Open Source ngx_http_rewrite_module heap buffer overflow remote code execution flaw (CVE-2026-42945)
Vulnerability
H score28
First: 14.05.2026 09:00
Last: 14.05.2026 09:00
Sources 1
About this happening:
CVE-2026-42945 exposes a heap buffer overflow in NGINX Plus and NGINX Open Source through ngx_http_rewrite_module, creating risk of unauthenticated remote co...
NGINX Plus and NGINX Open Source ngx_http_rewrite_module heap buffer overflow remote code execution flaw (CVE-2026-42945)
VulnerabilityAbout this happening: CVE-2026-42945 exposes a heap buffer overflow in NGINX Plus and NGINX Open Source through ngx_http_rewrite_module, creating risk of unauthenticated remote co...
Timeline
-
18.06.2026 14:33 3 articles · 27d ago
F5 releases out-of-band NGINX security updates
Mitigation Patch UpdateF5 released out-of-band security updates for NGINX to address CVE-2026-42530 and CVE-2026-42055 in ngx_http_v3_module, ngx_http_proxy_v2_module, and ngx_http_grpc_module, with fixes also covering NGINX Plus, NGINX Open Source, NGINX Gateway Fabric, and NGINX Instance Manager. The flaws can let unauthenticated remote attackers on non-default configurations trigger denial-of-service or code execution, and F5 advised temporary mitigations such as disabling HTTP/3 for CVE-2026-42530 and removing ignore_invalid_headers off while reducing large_client_header_buffers for CVE-2026-42055 when patching is delayed.
Show sources
- F5 issues out-of-band patches for critical NGINX vulnerabilities — www.bleepingcomputer.com — 18.06.2026 14:33
- F5 issues out-of-band patches for critical NGINX vulnerabilities — www.bleepingcomputer.com — 18.06.2026 14:33
- F5 Patches Two Critical NGINX Open Source Flaws Enabling Remote Code Execution — thehackernews.com — 18.06.2026 20:32