Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4355 articles · 196337 vulns · 36/41 feeds (7d)
← Back to list
8.1
CVE-2026-42055PATCHED
f5 · dos

NGINX ngx_http_proxy_v2_module and ngx_http_grpc_module vulnerability

Description

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass directives are used to proxy HTTP/2 traffic, the ignore_invalid_headers directive is set to off, and the large_client_header_buffers directive size is larger than 2 megabytes. A remote, unauthenticated attacker, along with conditions beyond their control, could send large headers while creating an upstream request. This may cause a heap-based buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected Products

VendorProductVersions
f5dos1.13.10, 1.30.2, 37.0, R36

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
f5wafcve_cpe95%
f5nginx_ingress_controllercve_cpe95%
f5nginx_instance_managercve_cpe95%
f5nginx_app_protect_doscve_cpe95%
f5nginx_gateway_fabriccve_cpe95%

References

  • https://my.f5.com/manage/s/article/K000161584(vendor-advisory)

Related News (7 articles)

Tier A
Microsoft MSRC53d ago
CVE-2026-42055 NGINX ngx_http_proxy_v2_module and ngx_http_grpc_module vulnerability
→ No new info (linked only)
Tier D
Heise Security65d ago
F5 patcht außerplanmäßig kritische Nginx-Sicherheitslücken
→ No new info (linked only)
Tier D
BleepingComputer66d ago
F5 issues out-of-band patches for critical NGINX vulnerabilities
→ No new info (linked only)
Tier B
BSI Advisories66d ago
[NEU] [hoch] NGINX und NGINX Plus: Mehrere Schwachstellen
→ No new info (linked only)
Tier B
CERT-FR67d ago
Multiples vulnérabilités dans Nginx (18 juin 2026)
→ No new info (linked only)
Tier C
VulDB67d ago
CVE-2026-42055 | F5 NGINX Open Source/NGINX Plus up to 1.30.2/1.31.1 heap-based overflow (K000161584)
→ No new info (linked only)
Tier C
oss-security94d ago
Host ambiguous requests through NGINX $host and Debian's proxy_params
→ No new info (linked only)
CVSS 3.18.1 HIGH
VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available
1.31.1
CWECWE-122
PublishedJun 17, 2026
Last enriched65d agov4
Tags
nginxhost headerdebianproxy_params
Trending Score0
Source articles7
Independent7
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

PRE-CVE
Multiple Vulnerabilities in F5 Products
MEDIUMCVE-2026-60062EXP
NGINX Agent Vulnerability
HIGHCVE-2026-55723EXP
NGINX Ingress Controller vulnerability
HIGHCVE-2026-42530EXP
NGINX Open-Source ngx_http_v3_module vulnerability
HIGHCVE-2026-50107EXP
NGINX Gateway Fabric vulnerability

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jun 17, 2026
Discovered by ZDM
Jun 17, 2026
Updated: severity, patchAvailable
Jun 17, 2026
Updated: cweIds
Jun 18, 2026
Updated: affectedVersions
Jun 19, 2026
Exploit Available
Jul 28, 2026
Patch Available
Jul 28, 2026

Version History

v4
Last enriched 65d ago
v4Tier D65d ago

Updated severity to CRITICAL, CVSS score to 9.2, added new affected versions, and marked exploit as available.

affectedVersions
via Heise Security
v3Tier D66d ago

Updated severity to CRITICAL, added new CWE-416, and marked the vulnerability as actively exploited.

cweIds
via BleepingComputer
v2Tier C67d ago

Updated severity to CRITICAL and patch available to version 1.31.1.

severitypatchAvailable
via VulDB
v167d ago

Initial creation