
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-42530 is a Use-after-Free (CWE-416) vulnerability in NGINX Open Source's ngx_http_v3_module (HTTP/3 QUIC module). A remote unauthenticated attacker can send a specially crafted HTTP/3 session to reopen a QPACK encoder stream, triggering a use-after-free condition in the NGINX worker process. This can cause a worker process restart (denial of service) and, on systems with ASLR disabled or where ASLR can be bypassed, may enable arbitrary code execution. Affected versions are NGINX Open Source 1.31.0 through 1.31.1 (fixed in 1.31.2). The vulnerability was disclosed on June 17, 2026, and carries a CVSS v3.1 score of 8.1 (High) and a CVSS v4.0 score of 9.2 (Critical) (Github Advisory, Red Hat Bugzilla).
The root cause is a Use-after-Free (CWE-416) in the ngx_http_v3_module QPACK encoder stream handling logic. When an HTTP/3 QUIC session is crafted to reopen an already-closed QPACK encoder stream, the NGINX worker process accesses memory that has already been freed, leading to undefined behavior. Exploitation requires the target NGINX instance to be configured with the HTTP/3 QUIC module enabled — a non-default configuration — and additional conditions beyond the attacker's direct control (e.g., specific timing or state). Code execution is conditional on ASLR being disabled or successfully bypassed; without this, the primary impact is a worker process crash and restart (Github Advisory, Red Hat Bugzilla).
Successful exploitation causes the NGINX worker process to crash and restart, resulting in a denial of service for active connections. On systems where ASLR is disabled or can be bypassed, an unauthenticated remote attacker may achieve arbitrary code execution with the privileges of the NGINX worker process, potentially leading to full system compromise, data exfiltration, or lateral movement within the network. The vulnerability affects confidentiality, integrity, and availability at the highest level under those conditions (Github Advisory).
nginx with QUIC/HTTP3 headers) or active probing for QUIC/UDP port 443 responses.ngx_http_v3_module is active and the server responds to HTTP/3 requests.worker process exited on signal); unusual QUIC session errors or QPACK stream-related error messages in error.log.F5 has released NGINX Open Source version 1.31.2 as the fix; upgrading to this version is the recommended remediation (Github Advisory). As an interim workaround if patching is not immediately possible, disable the HTTP/3 QUIC module (ngx_http_v3_module) in the NGINX configuration by removing or commenting out listen ... quic directives and reloading NGINX. Additionally, ensure ASLR is enabled on all systems running NGINX to significantly raise the bar for code execution exploitation. Fedora packages have also been updated; Linux distribution users should apply vendor-provided package updates as they become available.
F5 issued an out-of-band security advisory (K000161616) for this vulnerability, reflecting the severity of the issue (Github Advisory). Coverage was broad across security media including BleepingComputer, SecurityWeek, The Hacker News, and CyberSecurityNews, with headlines emphasizing the critical CVSS 9.2 score and the potential for unauthenticated remote code execution. Security researchers on Reddit (r/netsec, r/cybersecurity) and Mastodon/Infosec.exchange discussed the ASLR dependency as a nuance that, while limiting full RCE in many environments, does not reduce the urgency of patching given the DoS impact and the prevalence of NGINX deployments. The NCSC Ireland and Belgium's CCB both issued advisories urging prompt patching.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."