Back to News
Vulnerabilities

Two Critical NGINX Open Source Flaws Enabling Remote Code Execution Patched

Cyber RTJune 18, 20263 min read
Two Critical NGINX Open Source Flaws Enabling Remote Code Execution Patched

F5 has issued security updates for two critical vulnerabilities in NGINX Open Source, CVE-2026-42530 and CVE-2026-42055, both with a CVSS score of 9.2. These flaws, involving use-after-free and heap-based buffer overflow issues, could allow remote code execution if exploited. Patches are available for affected versions. F5 advises disabling HTTP/3 and adjusting configuration settings as mitigations. No active exploitation has been reported yet.

F5 has issued security updates to address two critical vulnerabilities in NGINX Open Source, which could allow attackers to execute code on affected systems. These vulnerabilities, identified as CVE-2026-42530 and CVE-2026-42055, both carry a high CVSS v4 score of 9.2, indicating their severity and potential impact on systems if exploited. The first vulnerability, CVE-2026-42530, is a use-after-free flaw in the ngx_http_v3_module. This can be exploited by a remote unauthenticated attacker when NGINX Open Source is configured to use the HTTP/3 QUIC module. The attacker can reopen a QPACK encoder stream using a specially crafted HTTP/3 session, potentially executing code on systems where Address Space Layout Randomization (ASLR) is disabled or bypassed. The second vulnerability, CVE-2026-42055, involves a heap-based buffer overflow in the ngx_http_proxy_v2_module and ngx_http_grpc_module. This flaw can be triggered under specific conditions, such as when proxy_http_version is set to 2 or grpc_pass directives are used, the ignore_invalid_headers directive is off, and the large_client_header_buffers directive size exceeds 2 MB. Similar to the first vulnerability, it allows code execution if ASLR is disabled or bypassed. F5 has released patches for these vulnerabilities in various versions of their products. For CVE-2026-42530, updates are available for NGINX Open Source, NGINX Gateway Fabric, NGINX Instance Manager, and NGINX Ingress Controller. For CVE-2026-42055, patches are provided for NGINX Plus, NGINX Open Source, NGINX Instance Manager, F5 WAF for NGINX, NGINX App Protect WAF, F5 DoS for NGINX, and NGINX Gateway Fabric, among others. To mitigate the risks associated with these vulnerabilities, F5 recommends disabling HTTP/3 for CVE-2026-42530. For CVE-2026-42055, users should remove the ignore_invalid_headers off directive from their configurations or reduce the large_client_header_buffers directive size to below 2 MB. Despite the lack of evidence that these vulnerabilities have been exploited in the wild, F5's products have a history of being targeted by malicious actors. This highlights the importance of applying security patches promptly to protect systems from potential threats. In a related incident, another critical security flaw in NGINX Plus and NGINX Open Source, known as CVE-2026-42945 or NGINX Rift, was actively exploited shortly after its public disclosure. This underscores the ongoing challenges in maintaining the security of widely-used software products. For those interested in staying informed about similar security updates and exclusive content, the article encourages following F5 on platforms like Google News, Twitter, and LinkedIn.