PT-2024-1647 · Nginx+1 · Nginx Plus+3

Published

2024-02-14

·

Updated

2025-11-11

·

CVE-2024-24989

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
The affected software is NGINX, specifically the HTTP/3 QUIC module in NGINX Plus and NGINX OSS. When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed requests can cause NGINX worker processes to terminate, potentially leading to a denial of service, related to a null pointer dereference. An exploit can be used to trigger this issue by sending specially crafted requests to the server. The vulnerable versions are not explicitly stated, but it's mentioned that software versions which have reached End of Technical Support (EoTS) are not evaluated. For more information, refer to the official NGINX documentation on QUIC and HTTP/3 support: https://nginx.org/en/docs/quic.html. #NGINX #NGINXPlus #NGINXOSS #HTTP3 #QUIC #DenialOfService #Exploit #cybersecurityawareness #infosec

Fix

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

BDU:2024-01321
BIT-NGINX-2024-24989
BIT-NGINX-GATEWAY-2024-24989
CVE-2024-24989
OPENSUSE-SU-2024:13701-1

Affected Products

Nginx Oss
Nginx Plus
Nginx
Red Os