CVE-2026-42530Patch(f5 / nginx_gateway_fabric)

CRITICALCVSS 9.2 · CRITICAL

Exploitation observed; activity peaked at 22 mentions and remains active

Immediate actions

  • Patch f5 nginx_gateway_fabric systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

NGINX Open Source has a vulnerability in the ngx_http_v3_module module. When NGINX Open Source is configured to use the HTTP/3 QUIC module, a remote unauthenticated attacker along with conditions beyond their control can use a specially crafted HTTP/3 session to reopen a QPACK encoder stream. This may cause a Use-after-Free in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

9.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • nginx_gateway_fabric
  • nginx_ingress_controller
  • nginx_instance_manager
  • nginx_open_source

Threat summary

  • Active exploitation appears in 5 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 74 mentions across 19 observed days

What's happening

  • Active exploitation reported across 5 signals
  • Exploit tool or code specified in 5 signals
  • PoC mentioned or linked in 8 signals
  • Patch or workaround mentioned in 44 signals
  • Technical details provided in 60 signals
  • Disclosure: 24 classified signals
  • Peaked 17d ago at 22 mentions (2026-06-18); latest day: 1
  • 74 total mentions across 19 days

Affected systems

Vendors
Products
nginx_gateway_fabricnginx_ingress_controllernginx_instance_managernginx_open_source

2 versions affected across 4 products

Deep dive

Activity timeline74 mentions / 19d
06111722Mentions · 2026-06-17: 2Mentions · 2026-06-18: 22Mentions · 2026-06-19: 20Mentions · 2026-06-20: 2Mentions · 2026-06-21: 3Mentions · 2026-06-22: 3Mentions · 2026-06-23: 1Mentions · 2026-06-24: 1Mentions · 2026-06-26: 3Mentions · 2026-06-27: 1Mentions · 2026-07-02: 1Mentions · 2026-07-03: 1Mentions · 2026-07-06: 1Mentions · 2026-07-12: 4Mentions · 2026-07-14: 2Mentions · 2026-07-25: 2Mentions · 2026-07-28: 1Mentions · 2026-07-30: 3Mentions · 2026-07-31: 1PoC Mentioned / Linked · 2026-06-19: 2PoC Mentioned / Linked · 2026-06-27: 1PoC Mentioned / Linked · 2026-07-25: 2PoC Mentioned / Linked · 2026-07-30: 3Exploit Tool / Code · 2026-06-19: 1Exploit Tool / Code · 2026-06-27: 1Exploit Tool / Code · 2026-07-25: 2Exploit Tool / Code · 2026-07-30: 1Active Exploitation · 2026-06-18: 2Active Exploitation · 2026-06-19: 1Active Exploitation · 2026-06-21: 1Active Exploitation · 2026-06-27: 1Patch / Workaround · 2026-06-17: 1Patch / Workaround · 2026-06-18: 17Patch / Workaround · 2026-06-19: 13Patch / Workaround · 2026-06-20: 1Patch / Workaround · 2026-06-21: 1Patch / Workaround · 2026-06-22: 2Patch / Workaround · 2026-06-23: 1Patch / Workaround · 2026-06-26: 1Patch / Workaround · 2026-06-27: 1Patch / Workaround · 2026-07-03: 1Patch / Workaround · 2026-07-06: 1Patch / Workaround · 2026-07-12: 3Patch / Workaround · 2026-07-30: 1Technical Details · 2026-06-17: 1Technical Details · 2026-06-18: 17Technical Details · 2026-06-19: 15Technical Details · 2026-06-20: 1Technical Details · 2026-06-21: 3Technical Details · 2026-06-22: 3Technical Details · 2026-06-23: 1Technical Details · 2026-06-24: 1Technical Details · 2026-06-26: 3Technical Details · 2026-06-27: 1Technical Details · 2026-07-03: 1Technical Details · 2026-07-06: 1Technical Details · 2026-07-12: 4Technical Details · 2026-07-14: 2Technical Details · 2026-07-25: 1Technical Details · 2026-07-28: 1Technical Details · 2026-07-30: 3Technical Details · 2026-07-31: 106-1706-1806-1906-2006-2106-2206-2306-2406-2606-2707-0207-0307-0607-1207-1407-2507-2807-3007-31
Signal classification6 categories
Patch
3648.6%
Disclosure
2432.4%
PoC
79.5%
Active Exploitation
34.1%
General
34.1%
Exploit
11.4%
Referenced assets55 URLs
By indicator
Classification over time
DateTotalLabels
2026-06-172
Disclosure1Patch1
2026-06-1822
Active Exploitation2Disclosure4General3Patch13
2026-06-1920
Active Exploitation1Disclosure4Patch13PoC2
2026-06-202
Disclosure1Patch1
2026-06-213
Disclosure2Patch1
2026-06-223
Disclosure1Patch2
2026-06-231
Disclosure1
2026-06-241
Disclosure1
2026-06-263
Disclosure2Patch1
2026-06-271
Exploit1
2026-07-021
Disclosure1
2026-07-031
Patch1
2026-07-061
Disclosure1
2026-07-124
Disclosure1Patch3
2026-07-142
Disclosure2
2026-07-252
PoC2
2026-07-281
Disclosure1
2026-07-303
PoC3
2026-07-311
Disclosure1
Full discourse20 posts
  • Nebula Security@nebusecurity
    Disclosure

    Here goes nginx-quicburst (CVE-2026-42530), a new RCE in Nginx discovered by our security agent VEGA and demonstrated by Nebula Security. This is only the third NGINX vulnerability since 2014 to receive NGINX’s “major” severity rating. If you use Nginx 1.31 with QUIC enabled, we recommend upgrading to the latest version. This bug has been patched in the latest Nginx release. We will publish the technical writeup, including the ASLR bypass, on July 18 together with the previous nginx-poolslip writeup.

    Post summary

    A new RCE (CVE-2026-42530) in Nginx has been disclosed, with a patch already released and an upcoming technical writeup detailing an ASLR bypass.

    121665813430105.6K
    6.7K followersView on X
  • Clandestine@akaclandestine
    Disclosure

    CVE-2026-42530 NGINX RCE https://t.co/iLIyZjJfRs

    Post summary

    The tweet announces a newly identified CVE-2026-42530 that grants remote code execution in NGINX, linking to additional details.

    12103178943857.9K
    63.3K followersView on X
  • Zhenpeng (Leo) Lin@Markak_
    PoC

    Open-sourcing our RCE implementation for CVE-2026-42533! This is an incredibly powerful NGINX bug that provides both info leak and an out-of-bounds heap write primitives (so, yes, ASLR bypass!). F5 released the security advisory a week ago on July 15th. Fun fact: this bug appears to have been found concurrently by multiple groups. Our team at @depthfirstlabs caught it using our internal systems, right alongside CVE-2026-42530, a separate issue in NGINX’s HTTP/3 QPACK implementation.

    Post summary

    The post announces the open‑source release of an RCE proof‑of‑concept for CVE‑2026‑42533, detailing info‑leak and OOB heap write primitives that bypass ASLR, but makes no claim of active exploitation or a patch.

    789337722730.5K
    3.6K followersView on X
  • The Hacker News@TheHackersNews
    Patch

    🚨 Two critical NGINX flaws can lead to remote code execution. F5 has patched: • CVE-2026-42530 (HTTP/3 use-after-free) • CVE-2026-42055 (HTTP/2 heap buffer overflow) Both require specific configurations and ASLR bypass conditions. Details here → https://thehackernews.com/2026/06/f5-patches-two-critical-nginx-open.html

    Post summary

    F5 has released patches for two critical NGINX vulnerabilities that could lead to remote code execution, with the notice providing specific technical details but no evidence of active exploitation or proof‑of‑concept.

    45961776254.4K
    2.2M followersView on X
  • moton@moton
    PoC

    CVE-2026-42530: NGINX HTTP/3 RCE PoC Disclosed - https://securityonline.info/nginx-http3-rce-cve-2026-42530/

    Post summary

    A proof‑of‑concept for CVE‑2026‑42530, an NGINX HTTP/3 remote code execution flaw, has been made public, but no details on active exploitation or patches are provided.

    04101576710.4K
    756 followersView on X
  • The Hacker News@TheHackersNews
    Patch

    Update: the critical NGINX flaws now have a clearer technical path. CVE-2026-42530 comes down to an HTTP/3 lifetime mismatch that can leave a freed stream pointer treated as valid. CVE-2026-42055 lets oversized HPACK data write past its buffer, causing unauthenticated worker crashes. Patch or apply mitigations. Read: https://thehackernews.com/2026/06/f5-patches-two-critical-nginx-open.html

    Post summary

    The post outlines technical details of two critical NGINX CVEs and urges applying patches or mitigations.

    13311122530.4K
    2.2M followersView on X
  • SOCRadar®@socradar
    Patch

    NGINX admins, your weekend might be starting early (and not in a good way). 🚨 F5 just dropped out-of-band fixes for two nasty NGINX flaws that can trigger remote DoS and potentially lead to RCE. 🔹 CVE-2026-42530 (HTTP/3 QUIC) 🔹 CVE-2026-42055 (HTTP/2 & gRPC proxying) Both can force worker restarts on exposed systems. Patch now to mitigate the risk and keep your servers humming. 🛠️ https://hubs.la/Q04l_j-00 #F5 #NGINX #CyberSecurity #VulnerabilityManagement #InfoSec

    Post summary

    F5 released out‑of‑band patches for two NGINX CVEs that enable remote DoS and possible RCE; administrators are urged to update immediately.

    36023133.2K
    6.6K followersView on X
  • Zhenpeng (Leo) Lin@Markak_
    PoC

    RCE implementation: https://github.com/DepthFirstDisclosures/Nginx-Rift/tree/main CVE-2026-42533 security advisory: https://my.f5.com/manage/s/article/K000162097 CVE-2026-42530 security advisory: https://my.f5.com/manage/s/article/K000161616

    Post summary

    The post provides a GitHub link to a proof‑of‑concept exploit for an RCE and references F5 advisories for CVE‑2026‑42533 and CVE‑2026‑42530 without indicating active exploitation or patches.

    03016172.0K
    3.6K followersView on X
  • dbugs@ptdbugs
    Disclosure

    ⚡️Analysis of the CVE-2026-42530 vulnerability in NGINX HTTP/3 PT ID: PT-2026-50439 This article examines the high-severity vulnerability CVE-2026-42530 discovered in the HTTP/3 (QUIC) implementation of the NGINX server, specifically within the QPACK handling logic. The researcher identified a use-after-free vulnerability that can be triggered by a remote attacker immediately after completing the QUIC handshake. In its simplest form, exploitation causes a worker process crash; however, with more precise heap grooming, the vulnerability can be leveraged to achieve arbitrary code execution. The root cause lies in a lifetime mismatch between objects: a pointer at the HTTP/3 session level continues to reference memory associated with a short-lived unidirectional stream. Once the stream is closed, the memory is freed, but the pointer is still considered valid by the program and continues to be used, leading to a use-after-free condition. 📎 Article : https://cystack.net/vi/research/cve-2026-42530-nginx-en#exploitation #dbugs_attacks

    Post summary

    The article discloses technical details of CVE-2026-42530, a high‑severity use‑after‑free in NGINX’s HTTP/3 implementation, outlining its root cause and potential for arbitrary code execution.

    020163848
    3.0K followersView on X
  • Nicolas Krassas@Dinosn
    Disclosure

    Use-after-free in the QPACK encoder of nginx HTTP/3 - CVE-2026-42530 https://cystack.net/vi/research/cve-2026-42530-nginx-en

    Post summary

    The notice announces a new use‑after‑free vulnerability in nginx HTTP/3's QPACK encoder (CVE‑2026‑42530) and provides a link for further details, but offers no PoC, exploit, or mitigation information.

    0101362.2K
    159.6K followersView on X
  • Trail of Bits@trailofbits
    Disclosure

    Remote and unauthenticated, it can crash nginx and potentially run code, all through HTTP/3. Engineer Evan Hellman found it with Codex after roughly 14 hours of automated analysis. CVE-2026-42530 in the dashboard: https://trailofbits.com/patch-the-planet/dashboard/

    Post summary

    CVE‑2026‑42530 is a remote, unauthenticated nginx vulnerability that can crash the server and potentially allow code execution through HTTP/3, discovered after automated analysis by Evan Hellman using Codex.

    0321041.6K
    39.3K followersView on X
  • Frank@jedisct1
    Patch

    nginx 1.30.3 and 1.31.2 released to fix CVE-2026-42055, CVE-2026-48142 and CVE-2026-42530 https://nginx.org

    Post summary

    The post announces nginx 1.30.3 and 1.31.2 releases that include fixes for three CVEs.

    011101839
    17.5K followersView on X
  • The CyberSec Guru@thecybersecguru
    PoC

    @akaclandestine Technical details behing Nginx;s CVE-2026-42530 & CVE-2026-42055..with PoCs and more https://thecybersecguru.com/news/nginx-cve-2026-42530-cve-2026-42055-rce/

    Post summary

    The tweet announces the existence of Proof‑of‑Concepts for Nginx CVE‑2026‑42530 and CVE‑2026‑42055, but offers no evidence of active exploitation, patches, or a debunking claim.

    010461.1K
    1.2K followersView on X
  • GovCERT.CZ@GOVCERT_CZ
    Patch

    🚨 Upozorňujeme na závažné zranitelnosti v NGINX, CVE-2026-42530 a CVE-2026-42055. CVE-2026-42530: jedná se o chybu typu use-after-free v modulu ngx_http_v3_module, která může být zneužita vzdáleným neautentizovaným útočníkem při použití HTTP/3 QUIC a speciálně vytvořené HTTP/3 relace k opětovnému otevření QPACK encoder streamu, což umožňuje spuštění libovolného kódu na systémech s deaktivovaným ASLR nebo při jeho obejití. CVE-2026-42055: jedná se o chybu typu heap-based buffer overflow v modulech ngx_http_proxy_v2_module a ngx_http_grpc_module, kterou lze zneužít při proxy provozu HTTP/2 za specifických konfiguračních podmínek (proxy_http_version nastaveno na 2 nebo grpc_pass, ignore_invalid_headers vypnuto a large_client_header_buffers větší než 2 MB), což rovněž umožňuje vzdálené spuštění kódu bez autentizace při neaktivním nebo obejitelném ASLR. Zranitelnosti ovlivňují více verzí NGINX Open Source, NGINX Plus, NGINX Ingress Controller, Gateway Fabric a dalších komponent, přičemž opravy jsou dostupné například ve verzích NGINX Open Source 1.31.2 a 1.30.3, NGINX Plus 37.0.2.1 nebo Gateway Fabric 2.6.4. 📌Doporučujeme aktualizovat na uvedené opravené verze a současně aplikovat mitigace: deaktivovat HTTP/3 pro CVE-2026-42530 a upravit konfiguraci (odstranit ignore_invalid_headers off nebo snížit large_client_header_buffers pod 2 MB) pro CVE-2026-42055.

    Post summary

    The post discloses two critical NGINX vulnerabilities, provides detailed technical information, and recommends specific patch versions and configuration mitigations to address them.

    03042598
    4.3K followersView on X
  • /r/netsec@_r_netsec
    Disclosure

    Use-after-free in the QPACK encoder of nginx HTTP/3 - CVE-2026-42530 https://cystack.net/vi/research/cve-2026-42530-nginx-en

    Post summary

    The message announces the discovery of a new use‑after‑free vulnerability in nginx’s QPACK encoder for HTTP/3 (CVE‑2026‑42530), with a link to a research article but no PoC, exploit code, or patch information.

    040401.2K
    33.6K followersView on X
  • ProjetoLabo@ProjetoLabo
    Active Exploitation

    Mais uma do NGIX, fica ligado desenvolvedor de SAAS em VPS. Duas brechas graves no NGINX, ambas nota 9.2, e a F5 lançou correção de emergência. O Nginx Rift já está sendo explorado desde maio. A CVE-2026-42530 é um erro de gerenciamento de memória no HTTP/3 que atinge as versões 1.31.0 e 1.31.1. A CVE-2026-42055 também corrompe a memória pelos módulos proxy. Nenhuma das duas exige autenticação e, sem a proteção de segurança do sistema (ASLR), viram execução remota de código. Mais duas falhas altas no Gateway Fabric, que expõem dados internos e deixam alterar configurações do servidor, além de duas médias. A F5 não esperou o ciclo normal de correção, a atualização saiu antes do previsto. NGINX roda em quase um terço dos servidores web do mundo. Seu servidor já está na 1.31.2 ou 1.30.3?

    Post summary

    The text advertises that CVE-2026-42530 and CVE-2026-42055 are actively exploited in NGINX, with emergency patches already released and explicit technical details indicating remote code execution via memory corruption.

    0102198
    190 followersView on X
  • The CyberSec Guru@thecybersecguru
    Patch

    Breaking: Two critical NGINX bugs just dropped. CVE-2026-42530: HTTP/3 QPACK UAF CVE-2026-42055: HTTP/2/gRPC heap overflow Remote. Unauthenticated. CVSS 9.2. Patches are live. Patch em before the exploit race starts: https://thecybersecguru.com/news/nginx-cve-2026-42530-cve-2026-42055-rce/

    Post summary

    The post announces two critical NGINX bugs, details their nature and severity, and stresses that patches are already available and should be applied promptly—no active exploitation or PoC information is provided.

    01011110
    970 followersView on X
  • Daily CyberSecurity@Daily_CyberSec
    PoC

    A public PoC now details CVE-2026-42530, an NGINX HTTP/3 RCE from a QPACK use-after-free. Upgrade to NGINX 1.31.2 to close the flaw now. #NGINX #HTTP3 #CVE202642530 #RCE #UseAfterFree #QUIC #QPACK #PoC #Cybersecurity http://securityonline.info/nginx-http3-rce-cve-2026-42530/

    Post summary

    A public PoC demonstrates an RCE in NGINX HTTP/3 via a QPACK use‑after‑free; patching to version 1.31.2 resolves the issue.

    01001478
    12.6K followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    NGINX の脆弱性 CVE-2026-42530/42055 が FIX:DoS と RCE の可能性 https://iototsecnews.jp/2026/06/18/f5-patches-nginx-vulnerability-enabling-code-execution-and-dos-attacks/ 人気の Web サーバ NGINX に、深刻な脆弱性 CVE-2026-42530/CVE-2026-42055 が発生しました。これらの問題の原因は、HTTP/2 や HTTP/3 を処理する内部プログラムにおいて、データの通り道を再度開いてしまう不整合や、特殊な接続要求を受け取った際のメモリ管理の不備にあります。これらの脆弱性が悪用されると、細工されたデータの送信によるサービス停止や、不正な命令の実行に至る危険性があります。ご利用のチームは、ご注意ください。 #CVE202611311 #CVE202642055 #CVE202642530 #CVE202650107 #nginx #Vulnerability

    Post summary

    The article announces the NGINX CVEs CVE‑2026‑42530 and CVE‑2026‑42055, details their internal causes and potential for DoS and RCE, but provides no exploit examples, patches, or evidence of active exploitation.

    01001129
    500 followersView on X
  • Jesús Morán | AI Infra@jamoran1356
    Patch

    F5 acaba de sacar patch de emergencia para NGINX: CVE-2026-42530. CVSS 9.2. Sin autenticación. Remote code execution. Si tu NGINX corre HTTP/3 (la versión moderna del protocolo web), tienes que actualizar HOY. Hilo: qué pasó y cómo detectar exposición

    Post summary

    The message announces an emergency patch for CVE-2026-42530, highlighting its high CVSS score and RCE risk, and urges immediate updates for NGINX servers using HTTP/3.

    1001053
    488 followersView on X
CPE platform detail6 entries

6 of 6 entries

PartVendorProductVersionTarget SWTarget HW
Appf5nginx_gateway_fabric---
Appf5nginx_ingress_controller---
Appf5nginx_ingress_controller4.0.0--
Appf5nginx_ingress_controller4.0.1--
Appf5nginx_instance_manager---
Appf5nginx_open_source---

Explore more