Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4355 articles · 196337 vulns · 36/41 feeds (7d)
← Back to list
8.1
CVE-2026-42530EXPLOITEDPATCHED
f5 · nginx open source

NGINX Open-Source ngx_http_v3_module vulnerability

Description

NGINX Open Source has a vulnerability in the ngx_http_v3_module module. When NGINX Open Source is configured to use the HTTP/3 QUIC module, a remote unauthenticated attacker along with conditions beyond their control can use a specially crafted HTTP/3 session to reopen a QPACK encoder stream. This may cause a Use-after-Free in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected Products

VendorProductVersions
f5nginx open source1.31.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
nginxnginx pluscert_advisory90%
nginxnginxcert_advisory90%

References

  • https://my.f5.com/manage/s/article/K000161616(vendor-advisory)

Related News (11 articles)

Tier D
The Hacker News44d ago
Unpatched XRING Flaw in XQUIC Lets Remote Clients Crash HTTP/3 Servers
→ No new info (linked only)
Tier E
Reddit r/cybersecurity65d ago
Use-after-free in the QPACK encoder of nginx HTTP/3 - CVE-2026-42530
→ No new info (linked only)
Tier E
Reddit r/netsec65d ago
Use-after-free in the QPACK encoder of nginx HTTP/3 - CVE-2026-42530
→ No new info (linked only)
Tier D
Heise Security65d ago
F5 patcht außerplanmäßig kritische Nginx-Sicherheitslücken
→ No new info (linked only)
Tier D
The Hacker News66d ago
F5 Patches Two Critical NGINX Open Source Flaws Enabling Remote Code Execution
→ No new info (linked only)
Tier E
Hacker News66d ago
CVE-2026-42530 – Nginx HTTP3/QUIC Use-After-Free
→ No new info (linked only)
Tier D
BleepingComputer66d ago
F5 issues out-of-band patches for critical NGINX vulnerabilities
→ No new info (linked only)
Tier B
BSI Advisories66d ago
[NEU] [hoch] NGINX und NGINX Plus: Mehrere Schwachstellen
→ No new info (linked only)
Tier B
CERT-FR67d ago
Multiples vulnérabilités dans Nginx (18 juin 2026)
→ No new info (linked only)
Tier E
Hacker News67d ago
CVE-2026-42530: Nginx 1.30.2 and Nginx 1.31.2
→ No new info (linked only)
Tier C
VulDB67d ago
CVE-2026-42530 | F5 NGINX Open Source up to 1.31.1 QUIC use after free (K000161616)
→ No new info (linked only)
CVSS 3.18.1 HIGH
VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
2.6.4
CWECWE-416
PublishedJun 17, 2026
Last enriched44d agov8
Tags
remote code executionheap-based buffer overflowNginx Gateway FabricNginx Ingress ControllerNginx Instant ManagerF5 WAF for NginxNginx App Protect WAFF5 DoS for NginxNginx App Protect DoS
Trending Score0
Source articles11
Independent9
Info Completeness10/14
Missing: epss, kev, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

PRE-CVE
Multiple Vulnerabilities in F5 Products
MEDIUMCVE-2026-60062EXP
NGINX Agent Vulnerability
HIGHCVE-2026-55723EXP
NGINX Ingress Controller vulnerability
HIGHCVE-2026-42055
NGINX ngx_http_proxy_v2_module and ngx_http_grpc_module vulnerability
HIGHCVE-2026-50107EXP
NGINX Gateway Fabric vulnerability

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jun 17, 2026
Discovered by ZDM
Jun 17, 2026
Updated: description, affectedVersions, severity, activelyExploited
Jun 17, 2026
Updated: cweIds
Jun 18, 2026
Updated: severity, exploitAvailable
Jun 18, 2026
Updated: description, cweIds, tags
Jun 18, 2026
Updated: affectedVersions, tags
Jun 19, 2026
Updated: affectedVersions, patchAvailable, tags
Jun 19, 2026
Updated: description
Jul 10, 2026
Actively Exploited
Jul 16, 2026
Exploit Available
Jul 16, 2026
Patch Available
Jul 16, 2026

Version History

v8
Last enriched 44d ago
v8Tier D44d ago

Added a detailed technical description of the XRING flaw in XQUIC and noted that there is no patch available.

description
via The Hacker News
v7Tier D65d ago

Updated affected versions to include Nginx Instant Manager and Nginx Ingress Controller, and added new tags related to additional products.

affectedVersionspatchAvailabletags
via Heise Security
v6Tier D65d ago

Updated affected versions to include 1.31.1 and added new tags related to heap-based buffer overflow and specific Nginx components.

affectedVersionstags
via Heise Security
v5Tier D66d ago

Updated CVSS score to 9.2, added new CWE-20, and provided a more detailed description of the vulnerability.

descriptioncweIdstags
via The Hacker News
v4Tier D66d ago

Updated severity to CRITICAL and marked exploit availability as true.

severityexploitAvailable
via BleepingComputer
v3Tier D66d ago

Updated severity to CRITICAL, added new CWE-787, and marked exploit availability as true.

cweIds
via BleepingComputer
v2Tier C67d ago

Updated description with new details, changed severity to CRITICAL, and added affected version 1.31.1.

descriptionaffectedVersionsseverityactivelyExploited
via VulDB
v167d ago

Initial creation