Cyber Alerts
MA-1467.062026: MyCERT Advisory - High-Severity Vulnerabilities in NGINX
Recently, F5 has released an out-of-band security update to address a use-after-free vulnerability in the ngx_http_v3_module (CVE-2026-42530) and a heap-based buffer overflow vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module (CVE-2026-42055) affecting NGINX.
- First observed
- 29 Jul 2026
- Last checked
- 01 Aug 2026
- Evidence records
- 1
- Publication state
- Published
What happened?
Current assessment
Recently, F5 has released an out-of-band security update to address a use-after-free vulnerability in the ngx_http_v3_module (CVE-2026-42530) and a heap-based buffer overflow vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module (CVE-2026-42055) affecting NGINX.
Why it matters
Successful exploitation of these vulnerabilities could lead to the following: CVE-2026-42530: Due to a use-after-free vulnerability in the ngx_http_v3_module, an unauthenticated attacker could send a crafted HTTP/3 session to crash the NGINX worker process, with potential remote code execution if ASLR is disabled or bypassed.CVE-2026-42055: Due to a heap-based buffer overflow vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module, an unauthenticated attacker could send oversized headers to crash the NGINX worker process, with potential remote code execution if ASLR is disabled or bypassed.
Who is affected?
Affected products and groups
For CVE-2026-42530: NGINX Open Source 1.x: versions 1.31.0 through 1.31.1NGINX Instance Manager 2.x: versions 2.17.0 through 2.22.0NGINX Gateway Fabric 2.x: versions 2.0.0 through 2.6.3NGINX Gateway Fabric 1.x: versions 1.3.0 through 1.6.2NGINX Ingress Controller 5.x: versions 5.0.0 through 5.5.0NGINX Ingress Controller 4.x: versions 4.0.0 through 4.0.1NGINX Ingress Controller 3.x: versions 3.5.0 through 3.7.2 For CVE-2026-42055: NGINX Plus 37.x: versions 37.0.0 through 37.0.1NGINX Plus Rx: versions R33 through R36NGINX Open Source 1.x: versions 1.31.1, and 1.30.0 through 1.30.2NGINX Instance Manager 2.x: versions 2.17.0 through 2.22.0F5 WAF for NGINX 5.x: versions 5.9.0 through 5.13.1NGINX App Protect WAF 5.x: versions 5.2.0 through 5.8.0NGINX App Protect WAF 4.x: versions 4.10.0 through 4.16.0F5 DoS for NGINX 4.x: version 4.9.0NGINX App Protect DoS 4.x: versions 4.3.0 through 4.7.0NGINX Gateway Fabric 2.x: versions 2.0.0 through 2.6.3NGINX Gateway Fabric 1.x: versions 1.3.0 through 1.6.2NGINX Ingress Controller 5.x: versions 5.0.0 through 5.5.0NGINX Ingress Controller 4.x: versions 4.0.0 through 4.0.1NGINX Ingress Controller 3.x: versions 3.5.0 through 3.7.2
What should you do now?
Actions from official guidance
For everyone
- CyberSecurity Malaysia encourages users and administrators to review NGINX Security Advisories and apply the necessary updates. Official source
- Generally, we advise users to be updated with the latest security announcements by the vendor and follow best practice security policies to determine which updates should be applied. Official source
Which sources support it?
Evidence and official sources
-
MyCERTOfficial sourceMA-1467.062026: MyCERT Advisory - High-Severity Vulnerabilities in NGINX
Recently, F5 has released an out-of-band security update to address a use-after-free vulnerability in the ngx_http_v3_module (CVE-2026-42530) and a heap-based buffer overflow vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module (CVE-2026-42055) affecting NGINX.
Published Just published · Retrieved 01 Aug 2026