Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.2

CVE-2026-42055: F5 NGINX Ingress Controller can crash from large HTTP/2 headers

CVE-2026-42055 · published 3 months ago
Summary

The F5 NGINX Ingress Controller and other F5 NGINX products may restart when they process HTTP/2 traffic with certain settings and receive very large request headers. An unauthenticated attacker could trigger this memory error, and if additional protections are disabled they might run their own code. Update to the latest version or adjust the configuration to limit header size and keep security features enabled.

What to do
  • Update nginx to version 1.31.2.
  • Update nginx-gateway-fabric to version 2.6.4.
  • Update canonical nginx to version 1.18.0-6ubuntu14.16.
  • Update canonical nginx to version 1.24.0-2ubuntu7.13.
  • Update canonical nginx to version 1.28.0-6ubuntu1.8.
  • Update canonical nginx to version 1.28.3-2ubuntu1.6.
  • Update bellsoft nginx to version 1.28.3-r6.
  • Update bellsoft nginx to version 1.30.3-r0.
  • Update alpine nginx to version 1.30.3-r0.
  • Update f5 nginx plus to version 37.0.2.1 or later.
  • Update f5 nginx open source to version 1.31.2 or later.
  • Update redhat update_infrastructure to version 5.2 or later.
Affected software
Ecosystem VendorProductAffected versions
– f5 dos 4.9.0
>= 4.3.0, <= 4.7.0
cpe:2.3:a:f5:dos:4.9.0:*:*:*:*:nginx:*:*
– f5 nginx_app_protect_dos >= 4.3.0, <= 4.7.0
cpe:2.3:a:f5:nginx_app_protect_dos:*:*:*:*:*:*:*:*
– f5 nginx_app_protect_waf >= 4.10.0, <= 4.16.0
>= 5.2.0, <= 5.8.0
cpe:2.3:a:f5:nginx_app_protect_waf:*:*:*:*:*:*:*:*
– f5 nginx_gateway_fabric >= 1.3.0, <= 1.6.2
>= 2.0.0, < 2.6.4
>= 2.0.0, <= 2.6.3
cpe:2.3:a:f5:nginx_gateway_fabric:*:*:*:*:*:*:*:*
– f5 nginx_ingress_controller 4.0.1
>= 3.5.0, <= 3.7.2
>= 5.0.0, < 5.5.1
4.0.0
>= 4.0.0, <= 4.0.1
>= 5.0.0, <= 5.5.0
cpe:2.3:a:f5:nginx_ingress_controller:4.0.1:*:*:*:*:*:*:*
– f5 nginx_instance_manager >= 2.17.0, <= 2.22.0
cpe:2.3:a:f5:nginx_instance_manager:*:*:*:*:*:*:*:*
– f5 nginx_open_source >= 1.30.0, < 1.30.3
1.31.1
>= 1.0.0, <= 1.30.2
>= 1.31.0, <= 1.31.1
cpe:2.3:a:f5:nginx_open_source:*:*:*:*:*:*:*:*
– f5 nginx_plus >= 37.0.0, <= 37.0.1
r3
r30
r31
r32
r33
r34
r35
r36
>= 37.0.0.1, < 37.0.2.1
>= r33, < r36
cpe:2.3:a:f5:nginx_plus:*:*:*:*:*:*:*:*
Bitnami – nginx >= 1.31.1, < 1.31.2
>= 1.13.10, < 1.31.2
>= 1.31.0, < 1.31.2
Fix: upgrade to 1.31.2
– f5 waf >= 5.9.0, <= 5.13.1
4.8.1
>= 5.2.0, <= 5.8.0
>= 4.10.0, <= 4.16.0
cpe:2.3:a:f5:waf:*:*:*:*:*:nginx:*:*
– f5 nginx plus < 37.0.2.1
Bitnami – nginx-gateway-fabric >= 1.3.0, < 2.6.4
Fix: upgrade to 2.6.4
Ubuntu:Pro:14.04:LTS canonical nginx All versions
Ubuntu:26.04:LTS canonical nginx < 1.28.3-2ubuntu1.6
Fix: upgrade to 1.28.3-2ubuntu1.6
Debian:11 debian nginx All versions
Debian:12 debian nginx All versions
Debian:13 debian nginx All versions
Debian:14 debian nginx All versions
Ubuntu:Pro:16.04:LTS canonical nginx All versions
Ubuntu:Pro:18.04:LTS canonical nginx All versions
Ubuntu:Pro:20.04:LTS canonical nginx All versions
Ubuntu:22.04:LTS canonical nginx < 1.18.0-6ubuntu14.16
Fix: upgrade to 1.18.0-6ubuntu14.16
Ubuntu:24.04:LTS canonical nginx < 1.24.0-2ubuntu7.13
Fix: upgrade to 1.24.0-2ubuntu7.13
Ubuntu:25.10 canonical nginx < 1.28.0-6ubuntu1.8
Fix: upgrade to 1.28.0-6ubuntu1.8
Alpaquita:25 bellsoft nginx >= 1.28.0-r3, < 1.28.3-r6
Fix: upgrade to 1.28.3-r6
Alpaquita:stream bellsoft nginx >= 1.22.1-r0, < 1.30.3-r0
Fix: upgrade to 1.30.3-r0
– f5 nginx open source < 1.31.2
Alpine:v3.24 alpine nginx < 1.30.3-r0
Fix: upgrade to 1.30.3-r0
– redhat discovery All versions
cpe:2.3:a:redhat:discovery:-:*:*:*:*:*:*:*
– redhat hardened_images All versions
cpe:2.3:a:redhat:hardened_images:-:*:*:*:*:*:*:*
– redhat update_infrastructure >= 5.0, < 5.2
cpe:2.3:a:redhat:update_infrastructure:*:*:*:*:*:*:*:*
– redhat enterprise_linux 8.0
9.0
10.0
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
Original advisory text
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass direc...
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass directives are used to proxy HTTP/2 traffic, the ignore_invalid_headers directive is set to off, and the large_client_header_buffers directive size is larger than 2 megabytes. A remote, unauthenticated attacker, along with conditions beyond their control, could send large headers while creating an upstream request. This may cause a heap-based buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR.


Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
References
Severity
9.2 Critical
CVSS 4.0: 9.4 (OSV)
CVSS 3.1: 8.1 (OSV)
Exploitation
EPSS 2%
Type
CWE-122Heap-based Buffer Overflow
CWE-787Out-of-bounds Write
CWE-131Incorrect Calculation of Buffer Size
Timeline
Published17 Jun 2026
Updated25 Sep 2026
First seen18 Jun 2026
Track software like this
Free during beta