CVE-2024-24989 Details
Description
When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed requests can cause NGINX worker processes to terminate. Note: The HTTP/3 QUIC module is not enabled by default and is considered experimental. For more information, refer to Support for QUIC and HTTP/3 https://nginx.org/en/docs/quic.html . NOTE: Software versions which have reached End of Technical Support (EoTS) are not evaluated
A denial-of-service vulnerability has been identified in NGINX Plus and NGINX Open Source versions 1.25.0 prior to 1.25.4, as well as in NGINX Plus R3x. When the experimental HTTP/3 QUIC module is enabled, undisclosed requests can lead to the termination of NGINX worker processes. This disruption causes a temporary outage as the NGINX process restarts.
Users can upgrade to NGINX versions 1.25.4 or 1.27.0. For NGINX Plus, the latest version is recommended. If an immediate upgrade is not possible, the HTTP/3 module can be disabled in the NGINX configuration.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 8, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://my.f5.com/manage/s/article/K000138444 | CVE | Vendor Advisory |
| http://www.openwall.com/lists/oss-security/2024/05/30/4 | CVE | Mailing List |
| https://my.f5.com/manage/s/article/K000138444 | [email protected] | Vendor Advisory |
| http://www.openwall.com/lists/oss-security/2024/05/30/4 | [email protected] | Mailing List |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-476 | NULL Pointer Dereference | [email protected] |
| CWE-476 | NULL Pointer Dereference | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| f5 nginx open source | 1.25.3 |
CPE
Remediation
| |
| f5 nginx plus | r31 - |
CPE
Remediation
| |
Change History
8 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 13, 2025 | CVE Modified | [email protected] |
| Jan 24, 2025 | Initial Analysis | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| Jun 10, 2024 | CVE Modified | [email protected] |
| May 14, 2024 | CVE Modified | [email protected] |
| Feb 14, 2024 | New CVE Received | [email protected] |