Vulnerability in NGINX Open Source's HTTP/3 Module
CVE-2026-42530

9.2CRITICAL

Key Information:

Vendor

F5

Vendor
CVE Published:
17 June 2026

Badges

🥇 Trended No. 1📈 Trended📈 Score: 6,500👾 Exploit Exists🟡 Public PoC📰 News Worthy

What is CVE-2026-42530?

CVE-2026-42530 is a critical vulnerability found in the NGINX Open Source software, specifically within its HTTP/3 module (ngx_http_v3_module). NGINX serves as a widely used web server and reverse proxy, playing a pivotal role in handling web traffic and providing high performance for web applications. This vulnerability allows unauthenticated remote attackers to manipulate the HTTP/3 session, potentially leading to a Use-after-Free condition in the NGINX worker process. The consequences can be severe, including service disruptions through unexpected restarts and, in some scenarios, unauthorized code execution on systems where security mechanisms such as Address Space Layout Randomization (ASLR) are either disabled or compromised. This risk signifies a major threat to organizations, especially those relying on NGINX for critical web infrastructure.

Potential impact of CVE-2026-42530

  1. Service Disruption: The exploitation of this vulnerability can cause NGINX to restart unexpectedly, which may lead to downtime for web applications, affecting business operations and user access.

  2. Remote Code Execution: If conditions permit, attackers may execute arbitrary code on affected systems, particularly those with reduced security measures. This situation can lead to unauthorized access and system compromise.

  3. Increased Security Attack Surface: The presence of this vulnerability may attract malicious actors looking to exploit weaknesses in NGINX deployments, leading to a higher likelihood of additional attacks, data breaches, and increased security risks for organizations.

Affected Version(s)

NGINX Open Source 1.31.0 < 1.31.2

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

News Articles

NGINX Vulnerability Patch: F5 Fixes Critical HTTP/3 and HTTP/2 Remote Code Execution Flaws

NGINX vulnerability patch is now critical: F5’s June 2026 out-of-band advisory covers two unauthenticated CVSS 9.2 flaws in HTTP/3 QUIC and HTTP/2 gRPC modules that can crash workers or enable remote

The ASLR Caveat on NGINX’s Critical HTTP/3 Flaw Changes Nothing About Urgency - IT Security News

CVE-2026-42530, the NGINX HTTP/3 vulnerability rated CVSS 9.2, is collecting dismissals because exploitation requires ASLR to be disabled or bypassed. Here is why that framing is wrong and why patching cannot wait. The ASLR Caveat on NGINX’s Critical HTTP/3 Flaw…Read more →

NGINX HTTP/3 Vulnerability: Why ASLR Won't Save You

The NGINX HTTP/3 vulnerability CVE-2026-42530 is 9.2 for good reason. Relying on ASLR to mitigate it ignores how real attacks work. Patch now.

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • 🥇

    Vulnerability reached the number 1 worldwide trending spot

  • 🟡

    Public PoC available

  • 📈

    Vulnerability started trending

  • 👾

    Exploit known to exist

  • 📰

    First article discovered by The Hacker News

  • Vulnerability published

  • Vulnerability Reserved

Credit

"F5 acknowledges Trung Nguyen (@everping) of CyStack, Zhenpeng (Leo) Lin (depthfirst), Evan Hellman (@xintenseapple) of Trail of Bits in collaboration with OpenAI, AntAISecurityLab, and Nebula Security (@nebusecurity) for bringing this issue to our attention and following the highest standards of coordinated disclosure."
.