Linuxsecurity
Multiple Vulnerabilities in NGINX Open Source and Plus Modules
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Two critical vulnerabilities have been identified in NGINX Open Source and Plus. CVE-2026-42055 affects the ngx_http_proxy_v2_module and ngx_http_grpc_module, allowing remote attackers to exploit large headers, potentially causing a heap-based buffer overflow and system restart. CVE-2026-42530 involves the ngx_http_v3_module, where attackers can exploit a specially crafted HTTP/3 session to cause a Use-after-Free condition, also leading to a system restart. Both vulnerabilities can allow code execution on systems with Address Space Layout Randomization (ASLR) disabled. The vulnerabilities are present in configurations that do not adhere to security best practices. No patches have been mentioned yet, and affected systems include those running specific versions of NGINX. Organizations are advised to review their configurations to mitigate potential risks.
Key Points: • CVE-2026-42055 allows remote attackers to exploit large headers in NGINX modules. • CVE-2026-42530 involves a Use-after-Free vulnerability in the HTTP/3 module. • Both vulnerabilities could lead to system restarts and code execution on vulnerable systems.