Cyber Alerts

MA-1467.062026: MyCERT Advisory - High-Severity Vulnerabilities in NGINX

Verified Officially confirmed

Recently, F5 has released an out-of-band security update to address a use-after-free vulnerability in the ngx_http_v3_module (CVE-2026-42530) and a heap-based buffer overflow vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module (CVE-2026-42055) affecting NGINX.

First observed
29 Jul 2026
Last checked
01 Aug 2026
Evidence records
1
Publication state
Published

What happened?

Current assessment

Recently, F5 has released an out-of-band security update to address a use-after-free vulnerability in the ngx_http_v3_module (CVE-2026-42530) and a heap-based buffer overflow vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module (CVE-2026-42055) affecting NGINX.

Why it matters

Successful exploitation of these vulnerabilities could lead to the following: CVE-2026-42530: Due to a use-after-free vulnerability in the ngx_http_v3_module, an unauthenticated attacker could send a crafted HTTP/3 session to crash the NGINX worker process, with potential remote code execution if ASLR is disabled or bypassed.CVE-2026-42055: Due to a heap-based buffer overflow vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module, an unauthenticated attacker could send oversized headers to crash the NGINX worker process, with potential remote code execution if ASLR is disabled or bypassed.

Who is affected?

Affected products and groups

For CVE-2026-42530: NGINX Open Source 1.x: versions 1.31.0 through 1.31.1NGINX Instance Manager 2.x: versions 2.17.0 through 2.22.0NGINX Gateway Fabric 2.x: versions 2.0.0 through 2.6.3NGINX Gateway Fabric 1.x: versions 1.3.0 through 1.6.2NGINX Ingress Controller 5.x: versions 5.0.0 through 5.5.0NGINX Ingress Controller 4.x: versions 4.0.0 through 4.0.1NGINX Ingress Controller 3.x: versions 3.5.0 through 3.7.2 For CVE-2026-42055: NGINX Plus 37.x: versions 37.0.0 through 37.0.1NGINX Plus Rx: versions R33 through R36NGINX Open Source 1.x: versions 1.31.1, and 1.30.0 through 1.30.2NGINX Instance Manager 2.x: versions 2.17.0 through 2.22.0F5 WAF for NGINX 5.x: versions 5.9.0 through 5.13.1NGINX App Protect WAF 5.x: versions 5.2.0 through 5.8.0NGINX App Protect WAF 4.x: versions 4.10.0 through 4.16.0F5 DoS for NGINX 4.x: version 4.9.0NGINX App Protect DoS 4.x: versions 4.3.0 through 4.7.0NGINX Gateway Fabric 2.x: versions 2.0.0 through 2.6.3NGINX Gateway Fabric 1.x: versions 1.3.0 through 1.6.2NGINX Ingress Controller 5.x: versions 5.0.0 through 5.5.0NGINX Ingress Controller 4.x: versions 4.0.0 through 4.0.1NGINX Ingress Controller 3.x: versions 3.5.0 through 3.7.2

What should you do now?

Actions from official guidance

For everyone

  1. CyberSecurity Malaysia encourages users and administrators to review NGINX Security Advisories and apply the necessary updates. Official source
  2. Generally, we advise users to be updated with the latest security announcements by the vendor and follow best practice security policies to determine which updates should be applied. Official source

Which sources support it?

Evidence and official sources

  1. MyCERTOfficial source
    MA-1467.062026: MyCERT Advisory - High-Severity Vulnerabilities in NGINX

    Recently, F5 has released an out-of-band security update to address a use-after-free vulnerability in the ngx_http_v3_module (CVE-2026-42530) and a heap-based buffer overflow vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module (CVE-2026-42055) affecting NGINX.

    Published Just published · Retrieved 01 Aug 2026