Vulnerability in NGINX Open Source's HTTP/3 Module
CVE-2026-42530
Key Information:
- Vendor
F5
- Status
- Vendor
- CVE Published:
- 17 June 2026
Badges
What is CVE-2026-42530?
CVE-2026-42530 is a critical vulnerability found in the NGINX Open Source software, specifically within its HTTP/3 module (ngx_http_v3_module). NGINX serves as a widely used web server and reverse proxy, playing a pivotal role in handling web traffic and providing high performance for web applications. This vulnerability allows unauthenticated remote attackers to manipulate the HTTP/3 session, potentially leading to a Use-after-Free condition in the NGINX worker process. The consequences can be severe, including service disruptions through unexpected restarts and, in some scenarios, unauthorized code execution on systems where security mechanisms such as Address Space Layout Randomization (ASLR) are either disabled or compromised. This risk signifies a major threat to organizations, especially those relying on NGINX for critical web infrastructure.
Potential impact of CVE-2026-42530
-
Service Disruption: The exploitation of this vulnerability can cause NGINX to restart unexpectedly, which may lead to downtime for web applications, affecting business operations and user access.
-
Remote Code Execution: If conditions permit, attackers may execute arbitrary code on affected systems, particularly those with reduced security measures. This situation can lead to unauthorized access and system compromise.
-
Increased Security Attack Surface: The presence of this vulnerability may attract malicious actors looking to exploit weaknesses in NGINX deployments, leading to a higher likelihood of additional attacks, data breaches, and increased security risks for organizations.
Affected Version(s)
NGINX Open Source 1.31.0 < 1.31.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
News Articles
NGINX Vulnerability Patch: F5 Fixes Critical HTTP/3 and HTTP/2 Remote Code Execution Flaws
NGINX vulnerability patch is now critical: F5’s June 2026 out-of-band advisory covers two unauthenticated CVSS 9.2 flaws in HTTP/3 QUIC and HTTP/2 gRPC modules that can crash workers or enable remote
The ASLR Caveat on NGINX’s Critical HTTP/3 Flaw Changes Nothing About Urgency - IT Security News
CVE-2026-42530, the NGINX HTTP/3 vulnerability rated CVSS 9.2, is collecting dismissals because exploitation requires ASLR to be disabled or bypassed. Here is why that framing is wrong and why patching cannot wait. The ASLR Caveat on NGINX’s Critical HTTP/3 Flaw…Read more →
NGINX HTTP/3 Vulnerability: Why ASLR Won't Save You
The NGINX HTTP/3 vulnerability CVE-2026-42530 is 9.2 for good reason. Relying on ASLR to mitigate it ignores how real attacks work. Patch now.
References
CVSS V4
Timeline
- 🥇
Vulnerability reached the number 1 worldwide trending spot
- 🟡
Public PoC available
- 📈
Vulnerability started trending
- 👾
Exploit known to exist
- 📰
First article discovered by The Hacker News
Vulnerability published
Vulnerability Reserved