Patch released NGINX Open Source network-edge NGINX Plus F5 web-app
F5 Patches Two Critical NGINX Flaws in HTTP/3 and HTTP/2 Modules (CVE-2026-42530, CVE-2026-42055)
CVE Tools coverage
F5 issued urgent out-of-band fixes for two high-impact NGINX vulnerabilities, CVE-2026-42530 (HTTP/3 use-after-free) and CVE-2026-42055 (conditional HTTP/2 heap-based buffer overflow). Both can be triggered by a remote, unauthenticated attacker and carry a CVSS v4.0 score of 9.2, with issues affecting NGINX worker process stability and potential security impact depending on system hardening. This matters because the flaws target widely deployed HTTP/2/HTTP/3 and specific NGINX module paths, so even limited configuration exposure can still affect a large number of deployments.