{"id":15859,"date":"2026-06-18T17:31:50","date_gmt":"2026-06-18T17:31:50","guid":{"rendered":"https:\/\/techtrendfeed.com\/?p=15859"},"modified":"2026-06-18T17:31:51","modified_gmt":"2026-06-18T17:31:51","slug":"f5-patches-nginx-vulnerability-enabling-code-execution-and-dos-assaults","status":"publish","type":"post","link":"https:\/\/techtrendfeed.com\/?p=15859","title":{"rendered":"F5 Patches NGINX Vulnerability Enabling Code Execution and DoS Assaults"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p class=\"wp-block-paragraph\">F5 has launched an out-of-band safety notification addressing<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/gbhackers.com\/new-nginx-0-day-rce-nginx-poolslip\/\" type=\"post\" id=\"186977\" target=\"_blank\" rel=\"noreferrer noopener\"> a number of excessive\u2011severity vulnerabilities in NGINX<\/a> elements that may allow distant code execution (RCE) and denial\u2011of\u2011service (DoS) assaults in sure configurations, urging clients to patch or improve affected deployments instantly.<\/p>\n<p class=\"wp-block-paragraph\">On June 17, 2026, <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/my.f5.com\/manage\/s\/article\/K000161614\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">F5 issued an out-of-band safety notification (K000161614) <\/a>summarizing a number of high- and medium-severity flaws throughout NGINX Open Supply, NGINX Plus, NGINX Occasion Supervisor, NGINX Gateway Material, NGINX Ingress Controller, and related App Shield WAF\/DoS modules. <\/p>\n<p class=\"wp-block-paragraph\">The advisory, up to date on June 18, 2026, highlights the elevated threat to HTTP\/2, HTTP\/3, and gRPC visitors dealing with paths and supplies clients with a consolidated view of impacted merchandise, variations, and stuck releases. <\/p>\n<p class=\"wp-block-paragraph\">This notification dietary supplements F5\u2019s common Quarterly Safety Notifications and is being echoed by nationwide CERTs, underscoring its urgency.<\/p>\n<h2 id=\"h-critical-nginx-http-3-v3-module-flaw-cve-2026-42530\" class=\"wp-block-heading\"><strong>Vital NGINX HTTP\/3 v3 Module Flaw (CVE-2026-42530)<\/strong><\/h2>\n<p class=\"wp-block-paragraph\">Essentially the most outstanding concern, tracked as CVE-2026-42530 and detailed in F5 article K000161616, impacts the NGINX ngx_http_v3_module when NGINX is configured to make use of the HTTP\/3 QUIC module. <\/p>\n<p class=\"wp-block-paragraph\">A distant, unauthenticated attacker can ship specifically crafted HTTP\/3 visitors to reopen a QPACK encoder stream, triggering a use-after-free within the NGINX employee course of that may repeatedly crash staff,<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/gbhackers.com\/nginx-poolslip-flaw-exposes-servers\/\" type=\"post\" id=\"187265\" target=\"_blank\" rel=\"noreferrer noopener\"> inflicting DoS<\/a>, and probably permitting code execution on techniques the place ASLR is disabled or might be bypassed. <\/p>\n<p class=\"wp-block-paragraph\">F5 assigns this bug a CVSS v3.1 base rating of 8.1 and a CVSS v4.0 base rating of 9.2, reflecting its high-to-critical affect profile on trendy deployments.<\/p>\n<p class=\"wp-block-paragraph\">A second high-severity concern, CVE-2026-42055 (K000161584), targets NGINX Plus and NGINX Open Supply when utilizing the ngx_http_proxy_v2_module or gRPC module with HTTP\/2 backends. <\/p>\n<p class=\"wp-block-paragraph\">When proxy_http_version is about to 2 or gRPC upstreams are enabled, malformed or malicious HTTP\/2 or gRPC streams can result in memory-handling flaws which will manifest as crashes and probably code execution, relying on the atmosphere\u2019s hardening. <\/p>\n<p class=\"wp-block-paragraph\">This flaw can also be rated at 8.1 (CVSS v3.1) and 9.2 (CVSS v4.0), aligning it with the HTTP\/3 vulnerability when it comes to severity from F5\u2019s perspective.<\/p>\n<p class=\"wp-block-paragraph\">F5 moreover discloses a number of high-severity vulnerabilities in NGINX Gateway Material, together with CVE-2026-11311 and CVE-2026-50107, described in K000161611 and K000161785, respectively. <\/p>\n<p class=\"wp-block-paragraph\">These points have an effect on numerous 2.x Gateway Material releases. They may end up in routing instability, service disruptions, or different impacts on integrity and availability inside service-mesh and gateway deployments. F5 introduces fixes in Gateway Material 2.6.4, which is now the beneficial goal model for affected clients.<\/p>\n<p class=\"wp-block-paragraph\" id=\"h-high-cve-matrix\"><strong>Excessive CVE Matrix<\/strong><\/p>\n<p class=\"wp-block-paragraph\">Beneath is a consolidated desk of the excessive\u2011severity CVEs and their core technical metadata as offered by F5, specializing in CVSS scores, affected merchandise, variations, and fixes.<\/p>\n<figure class=\"wp-block-table is-style-stripes\">\n<table class=\"has-fixed-layout\">\n<thead>\n<tr>\n<th class=\"has-text-align-left\" data-align=\"left\">CVE \/ Article<\/th>\n<th class=\"has-text-align-left\" data-align=\"left\">CVSS v3.1<\/th>\n<th class=\"has-text-align-left\" data-align=\"left\">CVSS v4.0<\/th>\n<th class=\"has-text-align-left\" data-align=\"left\">Affected merchandise<\/th>\n<th class=\"has-text-align-left\" data-align=\"left\">Affected variations<\/th>\n<th class=\"has-text-align-left\" data-align=\"left\">Fastened in<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>CVE-2026-42530 (K000161616)<\/td>\n<td>8.1 (Excessive)<\/td>\n<td>9.2 (Vital)<\/td>\n<td>NGINX Open Supply<a rel=\"nofollow\" target=\"_blank\" rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/my.f5.com\/manage\/s\/article\/K000161614\"\/><\/td>\n<td>1.31.0 \u2013 1.31.1<a rel=\"nofollow\" target=\"_blank\" rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/my.f5.com\/manage\/s\/article\/K000161614\"\/><\/td>\n<td>1.31.2<a rel=\"nofollow\" target=\"_blank\" rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/my.f5.com\/manage\/s\/article\/K000161614\"\/><\/td>\n<\/tr>\n<tr>\n<td\/>\n<td\/>\n<td\/>\n<td>NGINX Occasion Supervisor<a rel=\"nofollow\" target=\"_blank\" rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/my.f5.com\/manage\/s\/article\/K000161614\"\/><\/td>\n<td>2.17.0 \u2013 2.22.0<a rel=\"nofollow\" target=\"_blank\" rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/my.f5.com\/manage\/s\/article\/K000161614\"\/><\/td>\n<td>None (no repair but)<a rel=\"nofollow\" target=\"_blank\" rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/my.f5.com\/manage\/s\/article\/K000161614\"\/><\/td>\n<\/tr>\n<tr>\n<td\/>\n<td\/>\n<td\/>\n<td>NGINX Gateway Material<a rel=\"nofollow\" target=\"_blank\" rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/my.f5.com\/manage\/s\/article\/K000161614\"\/><\/td>\n<td>2.0.0 \u2013 2.6.3, 1.3.0 \u2013 1.6.2<a rel=\"nofollow\" target=\"_blank\" rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/my.f5.com\/manage\/s\/article\/K000161614\"\/><\/td>\n<td>2.6.4<a rel=\"nofollow\" target=\"_blank\" rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/my.f5.com\/manage\/s\/article\/K000161614\"\/><\/td>\n<\/tr>\n<tr>\n<td\/>\n<td\/>\n<td\/>\n<td>NGINX Ingress Controller<a rel=\"nofollow\" target=\"_blank\" rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/my.f5.com\/manage\/s\/article\/K000161614\"\/><\/td>\n<td>5.0.0 \u2013 5.5.0, 4.0.0 \u2013 4.0.1, 3.5.0 \u2013 3.7.2<a rel=\"nofollow\" target=\"_blank\" rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/my.f5.com\/manage\/s\/article\/K000161614\"\/><\/td>\n<td>None (no repair but)<a rel=\"nofollow\" target=\"_blank\" rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/my.f5.com\/manage\/s\/article\/K000161614\"\/><\/td>\n<\/tr>\n<tr>\n<td>CVE-2026-42055 (K000161584)<\/td>\n<td>8.1 (Excessive)<\/td>\n<td>9.2 (Vital)<\/td>\n<td>NGINX Plus<a rel=\"nofollow\" target=\"_blank\" rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/my.f5.com\/manage\/s\/article\/K000161614\"\/><\/td>\n<td>37.0.0 \u2013 37.0.1, R33 \u2013 R36<a rel=\"nofollow\" target=\"_blank\" rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/my.f5.com\/manage\/s\/article\/K000161614\"\/><\/td>\n<td>37.0.2.1, R36 P6<a rel=\"nofollow\" target=\"_blank\" rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/my.f5.com\/manage\/s\/article\/K000161614\"\/><\/td>\n<\/tr>\n<tr>\n<td\/>\n<td\/>\n<td\/>\n<td>NGINX Open Supply<a rel=\"nofollow\" target=\"_blank\" rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/my.f5.com\/manage\/s\/article\/K000161614\"\/><\/td>\n<td>1.31.1, 1.30.0 \u2013 1.30.2<a rel=\"nofollow\" target=\"_blank\" rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/my.f5.com\/manage\/s\/article\/K000161614\"\/><\/td>\n<td>1.31.2, 1.30.3<a rel=\"nofollow\" target=\"_blank\" rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/my.f5.com\/manage\/s\/article\/K000161614\"\/><\/td>\n<\/tr>\n<tr>\n<td\/>\n<td\/>\n<td\/>\n<td>NGINX Occasion Supervisor<a rel=\"nofollow\" target=\"_blank\" rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/my.f5.com\/manage\/s\/article\/K000161614\"\/><\/td>\n<td>2.17.0 \u2013 2.22.0<a rel=\"nofollow\" target=\"_blank\" rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/my.f5.com\/manage\/s\/article\/K000161614\"\/><\/td>\n<td>None<a rel=\"nofollow\" target=\"_blank\" rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/my.f5.com\/manage\/s\/article\/K000161614\"\/><\/td>\n<\/tr>\n<tr>\n<td\/>\n<td\/>\n<td\/>\n<td>F5 WAF for NGINX<\/td>\n<td>5.9.0 \u2013 5.13.1<a rel=\"nofollow\" target=\"_blank\" rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/my.f5.com\/manage\/s\/article\/K000161614\"\/><\/td>\n<td>None<a rel=\"nofollow\" target=\"_blank\" rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/my.f5.com\/manage\/s\/article\/K000161614\"\/><\/td>\n<\/tr>\n<tr>\n<td\/>\n<td\/>\n<td\/>\n<td>NGINX App Shield WAF<\/td>\n<td>5.2.0 \u2013 5.8.0, 4.10.0 \u2013 4.16.0<a rel=\"nofollow\" target=\"_blank\" rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/my.f5.com\/manage\/s\/article\/K000161614\"\/><\/td>\n<td>None<a rel=\"nofollow\" target=\"_blank\" rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/my.f5.com\/manage\/s\/article\/K000161614\"\/><\/td>\n<\/tr>\n<tr>\n<td\/>\n<td\/>\n<td\/>\n<td>F5 DoS for NGINX<\/td>\n<td>4.9.0<a rel=\"nofollow\" target=\"_blank\" rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/my.f5.com\/manage\/s\/article\/K000161614\"\/><\/td>\n<td>None<a rel=\"nofollow\" target=\"_blank\" rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/my.f5.com\/manage\/s\/article\/K000161614\"\/><\/td>\n<\/tr>\n<tr>\n<td\/>\n<td\/>\n<td\/>\n<td>NGINX App Shield DoS<\/td>\n<td>4.3.0 \u2013 4.7.0<a rel=\"nofollow\" target=\"_blank\" rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/my.f5.com\/manage\/s\/article\/K000161614\"\/><\/td>\n<td>None<a rel=\"nofollow\" target=\"_blank\" rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/my.f5.com\/manage\/s\/article\/K000161614\"\/><\/td>\n<\/tr>\n<tr>\n<td\/>\n<td\/>\n<td\/>\n<td>NGINX Gateway Material<a rel=\"nofollow\" target=\"_blank\" rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/my.f5.com\/manage\/s\/article\/K000161614\"\/><\/td>\n<td>2.0.0 \u2013 2.6.3, 1.3.0 \u2013 1.6.2<a rel=\"nofollow\" target=\"_blank\" rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/my.f5.com\/manage\/s\/article\/K000161614\"\/><\/td>\n<td>None<a rel=\"nofollow\" target=\"_blank\" rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/my.f5.com\/manage\/s\/article\/K000161614\"\/><\/td>\n<\/tr>\n<tr>\n<td\/>\n<td\/>\n<td\/>\n<td>NGINX Ingress Controller<a rel=\"nofollow\" target=\"_blank\" rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/my.f5.com\/manage\/s\/article\/K000161614\"\/><\/td>\n<td>5.0.0 \u2013 5.5.0, 4.0.0 \u2013 4.0.1, 3.5.0 \u2013 3.7.2<a rel=\"nofollow\" target=\"_blank\" rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/my.f5.com\/manage\/s\/article\/K000161614\"\/><\/td>\n<td>None<a rel=\"nofollow\" target=\"_blank\" rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/my.f5.com\/manage\/s\/article\/K000161614\"\/><\/td>\n<\/tr>\n<tr>\n<td>CVE-2026-11311 (K000161611)<\/td>\n<td>8.1 (Excessive)<a rel=\"nofollow\" target=\"_blank\" rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/my.f5.com\/manage\/s\/article\/K000161614\"\/><\/td>\n<td>8.6 (Excessive)<a rel=\"nofollow\" target=\"_blank\" rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/my.f5.com\/manage\/s\/article\/K000161614\"\/><\/td>\n<td>NGINX Gateway Material<a rel=\"nofollow\" target=\"_blank\" rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/my.f5.com\/manage\/s\/article\/K000161614\"\/><\/td>\n<td>2.5.0 \u2013 2.6.3<a rel=\"nofollow\" target=\"_blank\" rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/my.f5.com\/manage\/s\/article\/K000161614\"\/><\/td>\n<td>2.6.4<a rel=\"nofollow\" target=\"_blank\" rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/my.f5.com\/manage\/s\/article\/K000161614\"\/><\/td>\n<\/tr>\n<tr>\n<td>CVE-2026-50107 (K000161785)<\/td>\n<td>8.1 (Excessive)<a rel=\"nofollow\" target=\"_blank\" rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/my.f5.com\/manage\/s\/article\/K000161614\"\/><\/td>\n<td>8.6 (Excessive)<a rel=\"nofollow\" target=\"_blank\" rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/my.f5.com\/manage\/s\/article\/K000161614\"\/><\/td>\n<td>NGINX Gateway Material<a rel=\"nofollow\" target=\"_blank\" rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/my.f5.com\/manage\/s\/article\/K000161614\"\/><\/td>\n<td>2.3.0 \u2013 2.6.3<a rel=\"nofollow\" target=\"_blank\" rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/my.f5.com\/manage\/s\/article\/K000161614\"\/><\/td>\n<td>2.6.4<a rel=\"nofollow\" target=\"_blank\" rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/my.f5.com\/manage\/s\/article\/K000161614\"\/><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p class=\"wp-block-paragraph\">F5 strongly recommends upgrading NGINX Open Supply to 1.31.2, NGINX Plus to 37.0.2.1 or R36 P6, NGINX Gateway Material to 2.6.4, and aligning Ingress Controller and App Shield elements with forthcoming patched releases as they turn into out there. <\/p>\n<p class=\"wp-block-paragraph\">Organizations unable to patch instantly ought to take into account turning off HTTP\/3 and QUIC help, proscribing HTTP\/2 and gRPC publicity, implementing strict entry controls, and hardening ASLR and different exploitation mitigations as interim measures. <\/p>\n<p class=\"wp-block-paragraph\">Directors are additional suggested to watch F5\u2019s quarterly safety notifications and vendor RSS\/e-mail channels to trace future updates and any modifications in exploitation standing.<\/p>\n<p class=\"has-text-align-center has-background wp-block-paragraph\" style=\"background:linear-gradient(135deg,rgb(238,238,238) 100%,rgb(169,184,195) 100%)\"><strong>Observe us on\u00a0<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/news.google.com\/publications\/CAAqKAgKIiJDQklTRXdnTWFnOEtEV2RpYUdGamEyVnljeTVqYjIwb0FBUAE?hl=en-IN&amp;gl=IN&amp;ceid=IN%3Aen\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google Information<\/a>,\u00a0<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.linkedin.com\/company\/cyber-threat-intel\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and\u00a0<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/x.com\/The_Cyber_News\" target=\"_blank\" rel=\"noreferrer noopener\">X<\/a>\u00a0to Get Prompt Updates and Set GBH as a Most well-liked Supply in\u00a0<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.google.com\/preferences\/source?q=https:\/\/gbhackers.com\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google<\/a>.<\/strong><\/p>\n<\/div>\n\n","protected":false},"excerpt":{"rendered":"<p>F5 has launched an out-of-band safety notification addressing a number of excessive\u2011severity vulnerabilities in NGINX elements that may allow distant code execution (RCE) and denial\u2011of\u2011service (DoS) assaults in sure configurations, urging clients to patch or improve affected deployments instantly. On June 17, 2026, F5 issued an out-of-band safety notification (K000161614) summarizing a number of high- [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":15861,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[58],"tags":[145,977,527,6546,2205,9101,6544,1061],"class_list":["post-15859","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-attacks","tag-code","tag-dos","tag-enabling","tag-execution","tag-nginx","tag-patches","tag-vulnerability"],"_links":{"self":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/15859","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=15859"}],"version-history":[{"count":1,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/15859\/revisions"}],"predecessor-version":[{"id":15860,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/15859\/revisions\/15860"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/media\/15861"}],"wp:attachment":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=15859"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=15859"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=15859"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}<!-- This website is optimized by Airlift. Learn more: https://airlift.net. Template:. Learn more: https://airlift.net. Template: 69d9690a190636c2e0989534. Config Timestamp: 2026-04-10 21:18:02 UTC, Cached Timestamp: 2026-06-18 20:12:40 UTC -->