PT-2026-40677 · F5+2 · Nginx Open Source+2
Published
2026-05-13
·
Updated
2026-06-09
·
CVE-2026-42926
CVSS v3.1
5.8
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
NGINX Open Source versions prior to 1.30.0
Description
When configured to proxy HTTP/2 traffic by setting
proxy http version to 2 and utilizing proxy set body, an attacker may inject frame headers and payload bytes to the upstream peer.Recommendations
Update to a version 1.30.0 or later.
As a temporary workaround, avoid using
proxy set body when proxy http version is set to 2.Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nginx Open Source
Nginx
Red Os