VDB

CVE-2026-42055

CVE-2026-42055 PUBLISHED CVSS 8.100000381469727 HIGH

CVE-2026-42530 (CVSS 8.1) is a Use-after-Free vulnerability in the HTTP/3 QUIC module (ngx_http_v3_module) of NGINX Open Source. Under specific conditions, a remote unauthenticated attacker can send a specially crafted HTTP/3 session that reopens a QPACK encoder stream, resulting in memory corruption within the NGINX worker process. CVE-2026-42055 (CVSS 8.1) is a Heap-Based Buffer Overflow vulnerability affecting the ngx_http_proxy_v2_module and ngx_http_grpc_module in NGINX Plus and NGINX Open Source. The flaw can be exploited when HTTP/2 traffic is proxied using specific non-default configurations. By sending specially crafted requests containing oversized headers, a remote unauthenticated attacker can trigger memory corruption in the NGINX worker process. Successful exploitation of either vulnerability may cause the affected worker process to restart, leading to a DoS condition. In environments where Address Space Layout Randomization (ASLR) is disabled or can be bypassed, exploitation could also result in arbitrary code execution. CVE-2026-11311 and CVE-2026-50107 (CVSS 8.1) are Injection vulnerabilities in the NGINX Gateway Fabric configuration generator when NGINX Plus is used as the data plane. Insufficient sanitisation of user-supplied values in certain Custom Resource Definitions (CRDs) allows arbitrary NGINX directives to be injected into generated configurations. An authenticated attacker with permission to create or modify affected CRDs could alter control plane configurations, redirect traffic, or otherwise impact NGINX Gateway Fabric functionality. These vulnerabilities affect the control plane only.

EPSS 6.54% · 93.3th percentile

Risk Scores

CVSS 3.1
8.100000381469727
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
6.54%
93.3th percentile

Affected Products

VendorProductVersions
NginxF5  NGINX Plus, NGINX Open Source, and NGINX Gateway Fabric

Timeline

  • Jun 17, 2026 CVE Published
  • Jun 18, 2026 EPSS Score
  • Jun 18, 2026 Coalition ESS Score
  • Jun 19, 2026 Security Advisory
  • Jul 8, 2026 Distribution Patch
  • Jul 8, 2026 Security Advisory
  • Jul 8, 2026 Distribution Patch
  • Jul 8, 2026 Security Advisory
  • Jul 8, 2026 Distribution Patch
  • Jul 8, 2026 Security Advisory
  • Jul 13, 2026 Distribution Patch
  • Jul 13, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›