CVE-2026-42530 Details
Description
NGINX Open Source has a vulnerability in the ngx_http_v3_module module. When NGINX Open Source is configured to use the HTTP/3 QUIC module, a remote unauthenticated attacker along with conditions beyond their control can use a specially crafted HTTP/3 session to reopen a QPACK encoder stream. This may cause a Use-after-Free in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
A use-after-free vulnerability has been identified in the NGINX Open Source HTTP/3 QUIC module, affecting versions 1.31.0 through 1.31.1. When this module is active, a remote, unauthenticated attacker can exploit the vulnerability by sending a specially crafted HTTP/3 session that reopens a QPACK encoder stream. This exploitation can lead to a use-after-free condition in the NGINX worker process, causing a denial-of-service by crashing the process and triggering a restart. Furthermore, on systems where Address Space Layout Randomization (ASLR) is disabled or can be bypassed, this vulnerability may allow for arbitrary code execution.
To address this vulnerability, users can upgrade to NGINX version 1.31.2 or later. If an immediate upgrade is not possible, HTTP/3 can be disabled by removing 'quic' from all 'listen' directives.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 17, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2026:20351 | redhat-SADP | |
| https://access.redhat.com/security/cve/CVE-2026-42530 | redhat-SADP | Third Party Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2489872 | redhat-SADP | Third Party Advisory |
| https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42530.json | redhat-SADP | Third Party Advisory |
| https://my.f5.com/manage/s/article/K000161616 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-416 | Use After Free | redhat-SADP |
| CWE-416 | Use After Free | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| f5 nginx gateway fabric | >= 1.3.0, <= 1.6.2 >= 2.0.0, < 2.6.4 |
CPE
Remediation
| |
| f5 nginx ingress controller | >= 3.5.0, <= 3.7.2 >= 5.0.0, < 5.5.1 4.0.0 4.0.1 |
CPE
Remediation
| |
| f5 nginx instance manager | >= 2.17.0, <= 2.22.0 |
CPE
Remediation
| |
| f5 nginx open source | >= 1.31.0, < 1.31.2 |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 16, 2026 | CVE Modified | redhat-SADP |
| Jul 15, 2026 | CVE Modified | redhat-SADP |
| Jul 2, 2026 | Initial Analysis | [email protected] |
| Jun 30, 2026 | CVE Modified | redhat-SADP |
| Jun 18, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | New CVE Received | [email protected] |