CVE-2024-24989
NGINX vulnerability analysis and mitigation

Overview

CVE-2024-24989 is a security vulnerability affecting NGINX Plus and NGINX OSS when configured to use the HTTP/3 QUIC module. The vulnerability was disclosed on February 14, 2024, and affects NGINX versions 1.25.0 through 1.25.3. The HTTP/3 QUIC module, which is not enabled by default and is considered experimental, can be exploited through undisclosed requests that cause NGINX worker processes to terminate (NVD, Security Online).

Technical details

The vulnerability has been assigned a CVSS v3.1 base score of 7.5 (HIGH) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H. The flaw is classified as a NULL Pointer Dereference (CWE-476). The vulnerability specifically affects systems where NGINX is compiled with the ngx_http_v3_module and has the 'quic' option enabled in the 'listen' directive within the configuration file (NVD).

Impact

The primary impact of this vulnerability is the potential for denial-of-service (DoS) attacks. When exploited, the vulnerability allows remote unauthenticated attackers to cause NGINX worker processes to crash, potentially disrupting service availability. This is particularly concerning for high-traffic websites relying on NGINX for web serving capabilities (Security Online).

Mitigation and workarounds

The primary mitigation is to upgrade to NGINX version 1.25.4 or later, which contains the fix for this vulnerability. If immediate upgrading is not possible, the only reliable workaround is to disable HTTP/3 functionality. It's important to note that since the HTTP/3 QUIC module is not enabled by default, only systems explicitly configured to use this experimental feature are affected (Security Online).

Additional resources


SourceThis report was generated using AI

Related NGINX vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2024-33452HIGH7.7
  • NGINXNGINX
  • libnginx-mod-http-lua
NoYesApr 22, 2025
CVE-2025-1695MEDIUM6.9
  • NGINXNGINX
  • nginx
NoYesMar 04, 2025
CVE-2025-53859MEDIUM6.3
  • NGINXNGINX
  • nginx:1.24::nginx-filesystem
NoYesAug 13, 2025
CVE-2024-7347MEDIUM5.7
  • NGINXNGINX
  • nginx:1.22::nginx-filesystem
NoYesAug 14, 2024
CVE-2025-23419MEDIUM5.3
  • NGINXNGINX
  • nginx
NoYesFeb 05, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management