CVE-2026-40460 Details
Description
When NGINX Plus or NGINX Open Source are configured to use the HTTP/3 QUIC module, an attacker may be able to spoof their source IP address allowing for bypass of authorization or bypass of rate limiting. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
A vulnerability exists in NGINX Plus versions 37.x and R3x (R32 - R36), as well as NGINX Open Source versions 1.25.0 through 1.30.0, when the HTTP/3 QUIC module is enabled. This vulnerability allows an attacker to spoof their source IP address, potentially bypassing authorization measures or rate limiting. Additionally, this spoofing could be exploited to cause a denial-of-service condition on the NGINX system.
Users can upgrade to NGINX Plus version 37.0.0 or NGINX Open Source version 1.31.0 or 1.30.1 to address this vulnerability. For NGINX Plus users, version 36 P4 is also available. If using NGINX Instance Manager, version 2.21.1 should be installed. F5 WAF for NGINX users should upgrade to version 5.12.1, while NGINX App Protect WAF users should move to version 5.8.0. For those using NGINX Gateway Fabric, version 2.6.0 is recommended. NGINX Ingress Controller users should upgrade to version 5.4.2, 4.0.1, or 3.7.2, depending on their current version.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 13, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://my.f5.com/manage/s/article/K000161068 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-290 | Authentication Bypass by Spoofing | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| f5 dos | >= 4.3.0, <= 4.7.0 4.8.0 |
CPE
Remediation
| |
| f5 nginx gateway fabric | >= 1.3.0, <= 1.6.2 >= 2.0.0, <= 2.6.0 |
CPE
Remediation
| |
| f5 nginx ingress controller | >= 3.5.0, <= 3.7.2 >= 4.0.0, <= 4.0.1 >= 5.0.0, <= 5.4.2 |
CPE
Remediation
| |
| f5 nginx instance manager | >= 2.16.0, <= 2.22.0 |
CPE
Remediation
| |
| f5 nginx open source | >= 1.25.0, <= 1.30.0 |
CPE
Remediation
| |
| f5 nginx plus | >= r32, <= r36 |
CPE
Remediation
| |
| f5 waf | >= 4.9.0, <= 4.16.0 >= 5.1.0, <= 5.8.0 >= 5.9.0, <= 5.12.1 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 29, 2026 | Initial Analysis | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 13, 2026 | New CVE Received | [email protected] |