F5 Patches Two Critical NGINX Open Source Flaws Enabling Remote Code Execution
F5 has released patches for two high-severity vulnerabilities affecting NGINX Open Source that could be exploited by unauthenticated remote attackers to achieve remote code execution (RCE): CVE-2026-42530 and CVE-2026-42055. The issues involve a use-after-free in ngx_http_v3_module when HTTP/3 QUIC is used, and a heap-based buffer overflow in ngx_http_proxy_v2_module/ngx_http_grpc_module when proxying HTTP/2 with specific settings, potentially impacting systems even with ASLR depending on attacker conditions. Users should update to the fixed versions listed by F5 (notably NGINX Open Source 1.31.2 for CVE-2026-42530 and 1.31.2 / 1.30.3 paths for CVE-2026-42055) and consider F5’s mitigations such as disabling HTTP/3 or removing/reducing the configuration options that enable the second flaw.