CVE-2026-42926 Details
Description
When NGINX Open Source is configured to proxy HTTP/2 traffic by setting proxy_http_version to 2, and also uses proxy_set_body, an attacker may be able to inject frame headers and payload bytes to the upstream peer. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
A vulnerability exists in NGINX Open Source versions 1.29.4 to 1.30.0, specifically within the ngx_http_proxy_v2_module. When configured to proxy HTTP/2 traffic and using the proxy_set_body directive, an attacker may inject HTTP/2 frame headers and payload bytes into the upstream connection. This injection can disrupt the synchronization between NGINX and the upstream HTTP/2 peer, leading to potential data handling issues.
To address this vulnerability, users should upgrade to NGINX versions 1.31.0 or 1.30.1. If using NGINX Instance Manager, upgrade to version 2.21.2 or later. For NGINX Gateway Fabric, version 2.6.1 or later is recommended. Additionally, ensure that the proxy_set_body argument does not exceed 16MiB, which may require adjusting large_client_header_buffers, client_body_buffer_size, or client_max_body_size. As a further precaution, switch the proxy_http_version directive to a version other than 2.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 13, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://my.f5.com/manage/s/article/K000161131 | [email protected] | MitigationVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-172 | Encoding Error | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| f5 nginx gateway fabric | >= 1.3.0, <= 1.6.2 >= 2.0.0, <= 2.6.0 |
CPE
Remediation
| |
| f5 nginx open source | >= 1.29.4, <= 1.30.0 |
CPE
Remediation
| |
| f5 nginx instance manager | >= 2.16.0, <= 2.22.0 |
CPE
Remediation
| |
| f5 nginx ingress controller | >= 3.5.0, <= 3.7.2 >= 4.0.0, <= 4.0.1 >= 5.0.0, <= 5.4.2 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 18, 2026 | Initial Analysis | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 13, 2026 | New CVE Received | [email protected] |