Multiple Vulnerabilities in NGINX Open Source and Plus Modules

Multiple Vulnerabilities in NGINX Open Source and Plus Modules

First seen 19 Jun 2026, 08:55 UTC nvd.nist.govLinuxsecurity 74% similarity 67.5

Article Content

Browse articles
ThreatCluster

Two critical vulnerabilities have been identified in NGINX Open Source and Plus. CVE-2026-42055 affects the ngx_http_proxy_v2_module and ngx_http_grpc_module, allowing remote attackers to exploit large headers, potentially causing a heap-based buffer overflow and system restart. CVE-2026-42530 involves the ngx_http_v3_module, where attackers can exploit a specially crafted HTTP/3 session to cause a Use-after-Free condition, also leading to a system restart. Both vulnerabilities can allow code execution on systems with Address Space Layout Randomization (ASLR) disabled. The vulnerabilities are present in configurations that do not adhere to security best practices. No patches have been mentioned yet, and affected systems include those running specific versions of NGINX. Organizations are advised to review their configurations to mitigate potential risks.

Key Points: • CVE-2026-42055 allows remote attackers to exploit large headers in NGINX modules. • CVE-2026-42530 involves a Use-after-Free vulnerability in the HTTP/3 module. • Both vulnerabilities could lead to system restarts and code execution on vulnerable systems.

ThreatCluster AI How this analysis works

Timeline

2026-06-19
CVE-2026-42055 published
A vulnerability in NGINX modules can lead to heap-based buffer overflow and system restarts.
nvd.nist.gov
2026-06-19
CVE-2026-42530 published
A Use-after-Free vulnerability in the NGINX HTTP/3 module can cause system restarts.
nvd.nist.gov

Community

Browse all →