CVE Tools
Back to feed
Research ESET Gentlemen ransomware malware

F5 Patches Two Critical NGINX Open Source Flaws Enabling Remote Code Execution

The Hacker News·By The Hacker News··2 min read
CVE Tools coverage

F5 has released patches for two high-severity vulnerabilities affecting NGINX Open Source that could be exploited by unauthenticated remote attackers to achieve remote code execution (RCE): CVE-2026-42530 and CVE-2026-42055. The issues involve a use-after-free in ngx_http_v3_module when HTTP/3 QUIC is used, and a heap-based buffer overflow in ngx_http_proxy_v2_module/ngx_http_grpc_module when proxying HTTP/2 with specific settings, potentially impacting systems even with ASLR depending on attacker conditions. Users should update to the fixed versions listed by F5 (notably NGINX Open Source 1.31.2 for CVE-2026-42530 and 1.31.2 / 1.30.3 paths for CVE-2026-42055) and consider F5’s mitigations such as disabling HTTP/3 or removing/reducing the configuration options that enable the second flaw.