← All CVEs

CVE-2026-42055

CRITICAL 9.2

Published 2026-06-17 · Last modified 2026-07-15

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass directives are used to proxy HTTP/2 traffic, the ignore_invalid_headers directive is set to off, and the large_client_header_buffers directive size is larger than 2 megabytes. A remote, unauthenticated attacker, along with conditions beyond their control, could send large headers while creating an upstream request. This may cause a heap-based buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

ELEVATED IMPACT

Severe if exploited (CVSS 9.2), but no known exploitation and low modeled probability. Patch on a normal cadence.

Exploitation likelihood

3.6%chance of exploitation in 30 days · 88th percentile

○ In CISA KEV ○ Public exploit / PoC

Impact if exploited

9.2CVSS 4.0 · CRITICAL

  • ConfidentialityHigh
  • IntegrityHigh
  • AvailabilityHigh

What an attacker needs

  • Access: Reachable over the network — no local access needed
  • Privileges: No account or privileges required
  • User interaction: No user interaction needed
  • Complexity: Needs a race window or specific setup
  • Requirements: Specific conditions must be present

✓ lowers the bar for an attacker · ⚠ raises it

Proof of concept & exploit code

Test against your own equipment

curl -s https://vulnpedia.com/cve/CVE-2026-42055/poc.jsonMachine-readable PoC index for this CVE (for automation).

Listed for defensive triage, patch verification, and authorized testing on systems you own. Machine-readable: /cve/CVE-2026-42055/poc.json

Affected

Vendors F5 Red Hat

Products Nginx Open Source Nginx Plus Red Hat Enterprise Linux 10 Red Hat Enterprise Linux 8 Red Hat Enterprise Linux 9 Red Hat Hardened Images Red Hat Openshift Data Foundation 4 Dos Nginx App Protect Dos Nginx App Protect Waf Nginx Gateway Fabric Nginx Ingress Controller

Weakness (CWE)

  • CWE-122: Heap-based Buffer Overflow
  • CWE-131: Incorrect Calculation of Buffer Size
  • CWE-787: Out-of-bounds write

CVSS vector

CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Known Affected Software Configurations

VendorProductVersion range
F5Dos4.9.0
F5Nginx App Protect Dos≥ 4.3.0 and ≤ 4.7.0
F5Nginx App Protect Waf≥ 4.10.0 and ≤ 4.16.0
F5Nginx App Protect Waf≥ 5.2.0 and ≤ 5.8.0
F5Nginx Gateway Fabric≥ 1.3.0 and ≤ 1.6.2
F5Nginx Gateway Fabric≥ 2.0.0 and < 2.6.4
F5Nginx Ingress Controller≥ 3.5.0 and ≤ 3.7.2
F5Nginx Ingress Controller≥ 5.0.0 and < 5.5.1
F5Nginx Ingress Controller4.0.0
F5Nginx Ingress Controller4.0.1
F5Nginx Instance Manager≥ 2.17.0 and ≤ 2.22.0
F5Nginx Open Source≥ 1.30.0 and < 1.30.3
F5Nginx Open Source1.31.1
F5Nginx Plus≥ 37.0.0 and ≤ 37.0.1
F5Nginx Plusr3
F5Nginx Plusr30
F5Nginx Plusr30
F5Nginx Plusr30
F5Nginx Plusr31
F5Nginx Plusr31
F5Nginx Plusr31
F5Nginx Plusr31
F5Nginx Plusr32
F5Nginx Plusr32
F5Nginx Plusr32
F5Nginx Plusr32
F5Nginx Plusr32
F5Nginx Plusr33
F5Nginx Plusr33
F5Nginx Plusr33
F5Nginx Plusr33
F5Nginx Plusr34
F5Nginx Plusr34
F5Nginx Plusr34
F5Nginx Plusr35
F5Nginx Plusr35
F5Nginx Plusr36
F5Nginx Plusr36
F5Nginx Plusr36
F5Nginx Plusr36
F5Nginx Plusr36
F5Nginx Plusr36
F5Waf≥ 5.9.0 and ≤ 5.13.1
F5Waf4.8.1

All CVSS metrics

  • HIGH 8.1 v3.1 · CNA Primary
    CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
  • CRITICAL 9.2 v4.0 · CNA Primary
    CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
  • HIGH 8.1 v3.1 · ADP Primary
    CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
  • CRITICAL 9.2 v4.0 · NVD Secondary
    CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • HIGH 8.1 v3.1 · NVD Secondary
    CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

References

Advisories

Sources: NVD · CVE.org · EPSS