CVE-2026-42530
NGINX Open-Source ngx_http_v3_module vulnerability
Description
NGINX Open Source has a vulnerability in the ngx_http_v3_module module. When NGINX Open Source is configured to use the HTTP/3 QUIC module, a remote unauthenticated attacker along with conditions beyond their control can use a specially crafted HTTP/3 session to reopen a QPACK encoder stream. This may cause a Use-after-Free in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CVE-2026-42530 is a high-impact bug in F5 NGINX Open Source when HTTP/3 (QUIC) is enabled, where a crafted network session can crash NGINX and potentially lead to more serious consequences; if you run F5 NGINX Open Source with HTTP/3 enabled, you should act soon.
CVSS Vector Breakdown
AV:NAttack VectorAC:HAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Attack Graph
Click technique nodes to view MITRE ATT&CK details. Scroll to zoom, drag to pan.
Exploitability
MITRE ATT&CK
2 techniquesReferences
Timeline
- В NGINX исправили сразу две критические RCE-уязвимостиru-ru·Хакер (xakep.ru)· Source-only·
- F5 Patches Two Critical NGINX Flaws in HTTP/3 and HTTP/2 Modules (CVE-2026-42530, CVE-2026-42055)en-us·Daily CyberSecurity (securityonline.info)· Summary only·
- F5 Patches Two Critical NGINX Open Source Flaws Enabling Remote Code Executionen·The Hacker News· Summary only·
- F5 issues out-of-band patches for critical NGINX vulnerabilitiesen-us·BleepingComputer· Summary only·
- F5 Patches Critical, High-Severity NGINX Vulnerabilitiesen-us·SecurityWeek· Summary only·
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-42530 and every CVE in our database. Create a free account — no credit card required.
Create Free Account