Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.2
CVE-2026-42055: F5 NGINX Ingress Controller can crash from large HTTP/2 headers
CVE-2026-42055 · published 3 months ago
Summary
The F5 NGINX Ingress Controller and other F5 NGINX products may restart when they process HTTP/2 traffic with certain settings and receive very large request headers. An unauthenticated attacker could trigger this memory error, and if additional protections are disabled they might run their own code. Update to the latest version or adjust the configuration to limit header size and keep security features enabled.
What to do
- Update nginx to version 1.31.2.
- Update nginx-gateway-fabric to version 2.6.4.
- Update canonical nginx to version 1.18.0-6ubuntu14.16.
- Update canonical nginx to version 1.24.0-2ubuntu7.13.
- Update canonical nginx to version 1.28.0-6ubuntu1.8.
- Update canonical nginx to version 1.28.3-2ubuntu1.6.
- Update bellsoft nginx to version 1.28.3-r6.
- Update bellsoft nginx to version 1.30.3-r0.
- Update alpine nginx to version 1.30.3-r0.
- Update f5 nginx plus to version 37.0.2.1 or later.
- Update f5 nginx open source to version 1.31.2 or later.
- Update redhat update_infrastructure to version 5.2 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | f5 | dos |
4.9.0 >= 4.3.0, <= 4.7.0 cpe:2.3:a:f5:dos:4.9.0:*:*:*:*:nginx:*:* |
| – | f5 | nginx_app_protect_dos |
>= 4.3.0, <= 4.7.0 cpe:2.3:a:f5:nginx_app_protect_dos:*:*:*:*:*:*:*:* |
| – | f5 | nginx_app_protect_waf |
>= 4.10.0, <= 4.16.0 >= 5.2.0, <= 5.8.0 cpe:2.3:a:f5:nginx_app_protect_waf:*:*:*:*:*:*:*:* |
| – | f5 | nginx_gateway_fabric |
>= 1.3.0, <= 1.6.2 >= 2.0.0, < 2.6.4 >= 2.0.0, <= 2.6.3 cpe:2.3:a:f5:nginx_gateway_fabric:*:*:*:*:*:*:*:* |
| – | f5 | nginx_ingress_controller |
4.0.1 >= 3.5.0, <= 3.7.2 >= 5.0.0, < 5.5.1 4.0.0 >= 4.0.0, <= 4.0.1 >= 5.0.0, <= 5.5.0 cpe:2.3:a:f5:nginx_ingress_controller:4.0.1:*:*:*:*:*:*:* |
| – | f5 | nginx_instance_manager |
>= 2.17.0, <= 2.22.0 cpe:2.3:a:f5:nginx_instance_manager:*:*:*:*:*:*:*:* |
| – | f5 | nginx_open_source |
>= 1.30.0, < 1.30.3 1.31.1 >= 1.0.0, <= 1.30.2 >= 1.31.0, <= 1.31.1 cpe:2.3:a:f5:nginx_open_source:*:*:*:*:*:*:*:* |
| – | f5 | nginx_plus |
>= 37.0.0, <= 37.0.1 r3 r30 r31 r32 r33 r34 r35 r36 >= 37.0.0.1, < 37.0.2.1 >= r33, < r36 cpe:2.3:a:f5:nginx_plus:*:*:*:*:*:*:*:* |
| Bitnami | – | nginx |
>= 1.31.1, < 1.31.2 >= 1.13.10, < 1.31.2 >= 1.31.0, < 1.31.2 Fix: upgrade to 1.31.2
|
| – | f5 | waf |
>= 5.9.0, <= 5.13.1 4.8.1 >= 5.2.0, <= 5.8.0 >= 4.10.0, <= 4.16.0 cpe:2.3:a:f5:waf:*:*:*:*:*:nginx:*:* |
| – | f5 | nginx plus | < 37.0.2.1 |
| Bitnami | – | nginx-gateway-fabric |
>= 1.3.0, < 2.6.4 Fix: upgrade to 2.6.4
|
| Ubuntu:Pro:14.04:LTS | canonical | nginx | All versions |
| Ubuntu:26.04:LTS | canonical | nginx |
< 1.28.3-2ubuntu1.6 Fix: upgrade to 1.28.3-2ubuntu1.6
|
| Debian:11 | debian | nginx | All versions |
| Debian:12 | debian | nginx | All versions |
| Debian:13 | debian | nginx | All versions |
| Debian:14 | debian | nginx | All versions |
| Ubuntu:Pro:16.04:LTS | canonical | nginx | All versions |
| Ubuntu:Pro:18.04:LTS | canonical | nginx | All versions |
| Ubuntu:Pro:20.04:LTS | canonical | nginx | All versions |
| Ubuntu:22.04:LTS | canonical | nginx |
< 1.18.0-6ubuntu14.16 Fix: upgrade to 1.18.0-6ubuntu14.16
|
| Ubuntu:24.04:LTS | canonical | nginx |
< 1.24.0-2ubuntu7.13 Fix: upgrade to 1.24.0-2ubuntu7.13
|
| Ubuntu:25.10 | canonical | nginx |
< 1.28.0-6ubuntu1.8 Fix: upgrade to 1.28.0-6ubuntu1.8
|
| Alpaquita:25 | bellsoft | nginx |
>= 1.28.0-r3, < 1.28.3-r6 Fix: upgrade to 1.28.3-r6
|
| Alpaquita:stream | bellsoft | nginx |
>= 1.22.1-r0, < 1.30.3-r0 Fix: upgrade to 1.30.3-r0
|
| – | f5 | nginx open source | < 1.31.2 |
| Alpine:v3.24 | alpine | nginx |
< 1.30.3-r0 Fix: upgrade to 1.30.3-r0
|
| – | redhat | discovery |
All versions
cpe:2.3:a:redhat:discovery:-:*:*:*:*:*:*:* |
| – | redhat | hardened_images |
All versions
cpe:2.3:a:redhat:hardened_images:-:*:*:*:*:*:*:* |
| – | redhat | update_infrastructure |
>= 5.0, < 5.2 cpe:2.3:a:redhat:update_infrastructure:*:*:*:*:*:*:*:* |
| – | redhat | enterprise_linux |
8.0 9.0 10.0 cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:* |
Original advisory text
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass direc...
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass directives are used to proxy HTTP/2 traffic, the ignore_invalid_headers directive is set to off, and the large_client_header_buffers directive size is larger than 2 megabytes. A remote, unauthenticated attacker, along with conditions beyond their control, could send large headers while creating an upstream request. This may cause a heap-based buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
References
- https://docs.bell-sw.com/security/cves/CVE-2026-42055 Vendor Advisory
- https://security-tracker.debian.org/tracker/CVE-2026-42055 Vendor Advisory
- https://security.alpinelinux.org/vuln/CVE-2026-42055 Vendor Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-42055 Third Party Advisory
- https://ubuntu.com/security/CVE-2026-42055 Third Party Advisory
- https://github.com/nginx/nginx/commit/58a7bc3406ac8b9dc0e0afafc69ba42df56009e3 Third Party Advisory
- https://github.com/nginx/nginx/commit/26d824ec3a2f819300edce0ab3b055751c9843ff Third Party Advisory
- https://ubuntu.com/security/notices/USN-8458-1 Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-42055 URL
- https://access.redhat.com/errata/RHSA-2026:36331 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:36364 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:36618 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:36639 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:27197 Third Party Advisory
- https://my.f5.com/manage/s/article/K000161584 Vendor Advisory
- https://github.com/nginx/nginx/commit/131be8514da8985b15b74150521afedbf9cc4ea3 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:38847 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:44481 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:46836 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:58981
- https://access.redhat.com/security/cve/CVE-2026-42055 Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2489866 Issue Tracking Third Party Advisory
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42055.json Third Party Advisory
Severity
9.2
Critical
CVSS 4.0: 9.4 (OSV)
CVSS 3.1: 8.1 (OSV)
Exploitation
EPSS 2%
Type
CWE-122Heap-based Buffer Overflow
CWE-787Out-of-bounds Write
CWE-131Incorrect Calculation of Buffer Size
Timeline
Published17 Jun 2026
Updated25 Sep 2026
First seen18 Jun 2026
Sources
CVE-2026-42055 · NVD
DEBIAN-CVE-2026-42055 · OSV
UBUNTU-CVE-2026-42055 · OSV
BELL-CVE-2026-42055 · OSV
CVE-2026-42055 · OSV
CVE-2026-42055 · MITRE
BIT-nginx-2026-42055 · OSV
ALPINE-CVE-2026-42055 · OSV
Track software like this
Free during beta