В NGINX исправили сразу две критические RCE-уязвимости
F5 has issued out-of-band patches for two critical remote code execution issues in NGINX that can be triggered under specific conditions, potentially leading to arbitrary code execution or denial of service. The flaws are tracked as CVE-2026-42530 (use-after-free in ngx_http_v3_module, exploitable via crafted HTTP/3 QUIC sessions) and CVE-2026-42055 (heap buffer overflow affecting ngx_http_proxy_v2_module and ngx_http_grpc_module with certain proxy/grpc settings and large headers). These vulnerabilities impact NGINX Open Source and related offerings such as NGINX Plus, NGINX Gateway Fabric, NGINX Instance Manager, and NGINX Ingress Controller, and they matter because exploitation can crash and restart the NGINX worker and, without ASLR, may enable code execution.