THE content discusses a critical vulnerability identified as CVE-2026-42530 affecting the F5 NGINX Open Source HTTP/3 module, rated 9.2 on the CVSS scale. This vulnerability, which allows remote code execution via a use-after-free flaw in QPACK header compression, requires no user authentication. Although there has been no confirmed exploitation yet, the risk includes denial-of-service attacks and potential code execution in vulnerable configurations. Affected versions are 1.31.0 and 1.31.1, with a fix available in 1.31.2. Users are advised to upgrade immediately or disable HTTP/3 to mitigate the risk.
CVE-2026-42530: NGINX HTTP/3 flaw allows remote code execution
CyberSIXT Evidence Panel
Article by CyberSIXT
Timeline Coverage
Swipe to explore timeline
-
CVE-2026-42530: NGINX HTTP/3 flaw allows remote code execution
securityonline.info
-
F5 releases patches for critical NGINX HTTP/3 and HTTP/2 flaws
socradar.io
-
F5 Patches Two Critical NGINX Flaws in HTTP/3 and HTTP/2 Modules (CVE-2026-42530, CVE-2026-42055)
securityonline.info
-
F5 Patches Critical NGINX Vulnerabilities Enabling Unauthenticated Code Execution
securityaffairs.com
-
F5 patches NGINX remote code flaws CVE-2026-42530, CVE-2026-42055
securityweek.com