CVE-2026-42055 Details
Description
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass directives are used to proxy HTTP/2 traffic, the ignore_invalid_headers directive is set to off, and the large_client_header_buffers directive size is larger than 2 megabytes. A remote, unauthenticated attacker, along with conditions beyond their control, could send large headers while creating an upstream request. This may cause a heap-based buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
A heap-based buffer overflow vulnerability has been identified in NGINX Plus (versions 37.0.0 to 37.0.1) and NGINX Open Source (versions 1.30.0 to 1.30.2 and 1.31.1) within the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability arises when proxying HTTP/2 traffic with the proxy_http_version set to 2 or using grpc_pass, while the ignore_invalid_headers directive is off and the large_client_header_buffers directive allows headers larger than 2 megabytes. Under these conditions, a remote, unauthenticated attacker could send large headers in an upstream request, potentially causing a heap-based buffer overflow in the NGINX worker process, leading to a crash. Furthermore, on systems with Address Space Layout Randomization (ASLR) disabled or where ASLR can be bypassed, this vulnerability could be exploited to execute arbitrary code.
To address this vulnerability, users can upgrade to NGINX Plus version 37.0.2.1 or NGINX Open Source versions 1.31.2 or 1.30.3. For NGINX Instance Manager, versions 2.22.0 and later should be used. If using NGINX App Protect WAF, upgrade to version 5.9.0 or later. For NGINX Gateway Fabric, version 2.6.4 or later is recommended. Users can also mitigate the vulnerability by removing the ignore_invalid_headers off directive from the configuration or by reducing the large_client_header_buffers directive size to below 2 megabytes.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 17, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-787 | Out-of-bounds Write | [email protected] |
| CWE-122 | Heap-based Buffer Overflow | [email protected] |
| CWE-131 | Incorrect Calculation of Buffer Size | redhat-SADP |
Affected Products
| Product | Versions |
|---|---|
| f5 dos | >= 4.3.0, <= 4.7.0 4.9.0 |
CPE
Remediation
| |
| f5 nginx gateway fabric | >= 1.3.0, <= 1.6.2 >= 2.0.0, <= 2.6.3 |
CPE
Remediation
| |
| f5 nginx ingress controller | >= 3.5.0, <= 3.7.2 >= 4.0.0, <= 4.0.1 >= 5.0.0, <= 5.5.0 |
CPE
Remediation
| |
| f5 nginx instance manager | >= 2.17.0, <= 2.22.0 |
CPE
Remediation
| |
| f5 nginx open source | >= 1.0.0, <= 1.30.2 >= 1.31.0, <= 1.31.1 |
CPE
Remediation
| |
| f5 nginx plus | >= 37.0.0.1, < 37.0.2.1 >= r33, < r36 r36 - r36 p1 r36 p2 r36 p3 r36 p4 r36 p5 |
CPE
Remediation
| |
| f5 waf | >= 4.10.0, <= 4.16.0 >= 5.2.0, <= 5.8.0 >= 5.9.0, <= 5.13.1 |
CPE
Remediation
| |
| redhat discovery | All versions |
CPE
Remediation
| |
| redhat hardened images | All versions |
CPE
Remediation
| |
| redhat update infrastructure | >= 5.0, < 5.2 |
CPE
Remediation
| |
| redhat enterprise linux | 8.0 9.0 10.0 |
CPE
Remediation
| |
Change History
16 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 14, 2026 | CVE Modified | redhat-SADP |
| Sep 14, 2026 | CVE Modified | [email protected] |
| Aug 25, 2026 | CVE Modified | redhat-SADP |
| Aug 11, 2026 | Reanalysis | [email protected] |
| Aug 10, 2026 | Modified Analysis | [email protected] |
| Jul 28, 2026 | CVE Modified | redhat-SADP |
| Jul 24, 2026 | CVE Modified | redhat-SADP |
| Jul 15, 2026 | CVE Modified | redhat-SADP |
| Jul 13, 2026 | CVE Modified | redhat-SADP |
| Jul 9, 2026 | CVE Modified | redhat-SADP |
| Jul 8, 2026 | CVE Modified | redhat-SADP |
| Jul 2, 2026 | Initial Analysis | [email protected] |
| Jun 30, 2026 | CVE Modified | redhat-SADP |
| Jun 18, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | New CVE Received | [email protected] |