NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass directi…
High CVSS 8.1
Summary
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass directives are used to proxy HTTP/2 traffic, the ignore_invalid_headers directive is set to off, and the large_client_header_buffers directive size is larger than 2 megabytes. A remote, unauthenticated attacker, along with conditions beyond their control, could send large headers while creating an upstream…
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
Sources
- NVD DATABASE
Original Links
- https://my.f5.com/manage/s/article/K000161584 Vendor Advisory
- https://access.redhat.com/errata/RHSA-2026:27197 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:36331 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:36364 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:36618 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:36639 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:38847 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:44481 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:46836 Third Party Advisory
- https://access.redhat.com/security/cve/CVE-2026-42055 Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2489866 Third Party Advisory
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42055.json Third Party Advisory
Timeline
- nvd_ingest NVD