CVE-2026-42530
NGINX Open-Source ngx_http_v3_module vulnerability
Description
NGINX Open Source has a vulnerability in the ngx_http_v3_module module. When NGINX Open Source is configured to use the HTTP/3 QUIC module, a remote unauthenticated attacker along with conditions beyond their control can use a specially crafted HTTP/3 session to reopen a QPACK encoder stream. This may cause a Use-after-Free in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
In plain language
AI Worth attentionCVE-2026-42530 is a high-impact bug in F5 NGINX Open Source when HTTP/3 (QUIC) is enabled, where a crafted network session can crash NGINX and potentially lead to more serious consequences; if you run F5 NGINX Open Source with HTTP/3 enabled, you should act soon.
What to do
- Check whether your F5 NGINX Open Source is configured with the HTTP/3 QUIC module (ngx_http_v3_module). 2) Update NGINX Open Source to the patched version your vendor provides (ask your IT/NGINX maintainer to confirm the exact target version). 3) After updating, verify HTTP/3 is still configured as intended and monitor NGINX for restarts or unusual HTTP/3 traffic.
CVSS Vector Breakdown
AV:NAttack VectorAC:HAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
- Unpatched XRING Flaw in XQUIC Lets Remote Clients Crash HTTP/3 Serversen·The Hacker News· Research XQUIC network-edge
- В NGINX исправили сразу две критические RCE-уязвимостиru-ru·Хакер (xakep.ru)· Patch NGINX Open Source rce
- F5 Patches Two Critical NGINX Flaws in HTTP/3 and HTTP/2 Modules (CVE-2026-42530, CVE-2026-42055)en-us·Daily CyberSecurity (securityonline.info)· Patch NGINX Open Source network-edge
- F5 Patches Two Critical NGINX Open Source Flaws Enabling Remote Code Executionen·The Hacker News· Research ESET Gentlemen
- F5 issues out-of-band patches for critical NGINX vulnerabilitiesen-us·BleepingComputer· Patch NGINX Plus rce
- F5 Patches Critical, High-Severity NGINX Vulnerabilitiesen-us·SecurityWeek· Patch NGINX Plus rce
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-42530 and every CVE in our database. Create a free account — no credit card required.
Create Free Account