PT-2024-1647 · Nginx+1 · Nginx Plus+3
Published
2024-02-14
·
Updated
2025-11-11
·
CVE-2024-24989
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
The affected software is NGINX, specifically the HTTP/3 QUIC module in NGINX Plus and NGINX OSS.
When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed requests can cause NGINX worker processes to terminate, potentially leading to a denial of service, related to a null pointer dereference.
An exploit can be used to trigger this issue by sending specially crafted requests to the server.
The vulnerable versions are not explicitly stated, but it's mentioned that software versions which have reached End of Technical Support (EoTS) are not evaluated.
For more information, refer to the official NGINX documentation on QUIC and HTTP/3 support: https://nginx.org/en/docs/quic.html.
#NGINX #NGINXPlus #NGINXOSS #HTTP3 #QUIC #DenialOfService #Exploit #cybersecurityawareness #infosec
Fix
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nginx Oss
Nginx Plus
Nginx
Red Os