Find notable cyber news and cases, enriched with sources, timelines, and signals.

NGINX web server critical flaws (multiple vulnerabilities)

Vulnerability
First reported
Last updated
Happening score
H score 38
2 unique sources, 2 articles

Summary

Hide ▲

NGINX had two critical web server vulnerabilities, CVE-2026-42530 and CVE-2026-42055, that can let remote unauthenticated attackers trigger remote code execution on affected deployments. The flaws affect ngx_http_v3_module, ngx_http_proxy_v2_module, and ngx_http_grpc_module in NGINX Open Source and related F5 products, especially when HTTP/3 QUIC or specific HTTP/2 proxy settings are enabled. F5 released security updates, with fixes including 1.31.2, 1.30.3, 2.6.4, 37.0.2.1, and R36 P6, and advised temporary mitigations such as disabling HTTP/3 or removing ignore_invalid_headers off and reducing large_client_header_buffers below 2 MB.

Related Happenings

XQUIC XRING remote crash security flaw

Vulnerability
H score1 First: 10.07.2026 14:47 Last: 10.07.2026 14:47 Sources 1

About this happening: XQUIC's XRING flaw leaves HTTP/3 servers exposed to remote crashes through valid QPACK traffic, with no patch available. The bug needs no login and no malforme...

NGINX and Apache HTTPD HTTP/2 Bomb mitigations

Advisory/Mitigation
H score46 First: 03.06.2026 11:33 Last: 03.06.2026 11:33 Sources 1

About this happening: Calif issued mitigation guidance for NGINX and Apache HTTPD operators after HTTP/2 Bomb was found to enable a remote denial-of-service against default HTTP/2 confi...

OpenDCIM multi-flaw exploitation wave (CVE-2026-28515, CVE-2026-28516, CVE-2026-28517)

Exploitation Wave
H score46 First: 17.05.2026 14:57 Last: 17.05.2026 14:57 Sources 1

About this happening: openDCIM is seeing an active exploitation wave tied to CVE-2026-28515, CVE-2026-28516, and CVE-2026-28517, with attackers targeting vulnerable installations an...

NGINX rewrite-rule workaround for CVE-2026-42945

Advisory/Mitigation
H score23 First: 14.05.2026 18:43 Last: 14.05.2026 18:43 Sources 1

About this happening: F5 issued a workaround for vulnerable NGINX rewrite rules, reducing exposure to CVE-2026-42945 for operators who cannot upgrade immediately. The guidance replaces...

NGINX Plus and NGINX Open Source ngx_http_rewrite_module heap buffer overflow remote code execution flaw (CVE-2026-42945)

Vulnerability
H score28 First: 14.05.2026 09:00 Last: 14.05.2026 09:00 Sources 1

About this happening: CVE-2026-42945 exposes a heap buffer overflow in NGINX Plus and NGINX Open Source through ngx_http_rewrite_module, creating risk of unauthenticated remote co...

Timeline

  1. 18.06.2026 14:33 3 articles · 27d ago

    F5 releases out-of-band NGINX security updates

    Mitigation Patch Update

    F5 released out-of-band security updates for NGINX to address CVE-2026-42530 and CVE-2026-42055 in ngx_http_v3_module, ngx_http_proxy_v2_module, and ngx_http_grpc_module, with fixes also covering NGINX Plus, NGINX Open Source, NGINX Gateway Fabric, and NGINX Instance Manager. The flaws can let unauthenticated remote attackers on non-default configurations trigger denial-of-service or code execution, and F5 advised temporary mitigations such as disabling HTTP/3 for CVE-2026-42530 and removing ignore_invalid_headers off while reducing large_client_header_buffers for CVE-2026-42055 when patching is delayed.

    Show sources