NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass directives are used to proxy HTTP/2 traffic, the ignore_invalid_headers directive is set to off, and the large_client_header_buffers directive size is larger than 2 megabytes. A remote, unauthenticated attacker, along with conditions beyond their control, could send large headers while creating an upstream request. This may cause a heap-based buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
History

Tue, 11 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Redhat
Redhat discovery
Redhat enterprise Linux
Redhat hardened Images
Redhat update Infrastructure
CPEs cpe:2.3:a:f5:nginx_ingress_controller:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_ingress_controller:4.0.0:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_ingress_controller:4.0.1:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_open_source:1.31.1:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_plus:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_plus:r30:-:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_plus:r30:p1:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_plus:r30:p2:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_plus:r31:-:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_plus:r31:p1:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_plus:r31:p2:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_plus:r31:p3:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_plus:r32:-:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_plus:r32:p1:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_plus:r32:p2:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_plus:r32:p3:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_plus:r32:p4:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_plus:r33:-:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_plus:r33:p1:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_plus:r33:p2:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_plus:r33:p3:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_plus:r34:-:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_plus:r34:p1:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_plus:r34:p2:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_plus:r35:-:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_plus:r35:p1:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_plus:r36:-:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_plus:r36:p1:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_plus:r36:p2:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_plus:r36:p3:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_plus:r36:p4:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_plus:r36:p5:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_plus:r3:*:*:*:*:*:*:*
cpe:2.3:a:f5:waf:4.8.1:*:*:*:*:nginx:*:*
cpe:2.3:a:f5:nginx_ingress_controller:*:*:*:*:continuous_releases:*:*:*
cpe:2.3:a:f5:nginx_plus:*:*:*:*:continuous_releases:*:*:*
cpe:2.3:a:f5:nginx_plus:*:*:*:*:long-term_support:*:*:*
cpe:2.3:a:f5:nginx_plus:r36:-:*:*:continuous_releases:*:*:*
cpe:2.3:a:f5:nginx_plus:r36:p1:*:*:continuous_releases:*:*:*
cpe:2.3:a:f5:nginx_plus:r36:p2:*:*:continuous_releases:*:*:*
cpe:2.3:a:f5:nginx_plus:r36:p3:*:*:continuous_releases:*:*:*
cpe:2.3:a:f5:nginx_plus:r36:p4:*:*:continuous_releases:*:*:*
cpe:2.3:a:f5:nginx_plus:r36:p5:*:*:continuous_releases:*:*:*
cpe:2.3:a:redhat:discovery:-:*:*:*:*:*:*:*
cpe:2.3:a:redhat:hardened_images:-:*:*:*:*:*:*:*
cpe:2.3:a:redhat:update_infrastructure:*:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
Vendors & Products Redhat
Redhat discovery
Redhat enterprise Linux
Redhat hardened Images
Redhat update Infrastructure

Fri, 26 Jun 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-131
References
Metrics threat_severity

None

threat_severity

Important


Thu, 18 Jun 2026 20:00:00 +0000

Type Values Removed Values Added
First Time appeared F5
F5 nginx Open Source
F5 nginx Plus
Vendors & Products F5
F5 nginx Open Source
F5 nginx Plus

Thu, 18 Jun 2026 04:45:00 +0000

Type Values Removed Values Added
Description NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass directives are used to proxy HTTP/2 traffic, the ignore_invalid_headers directive is set to off, and the large_client_header_buffers directive size is larger than 2 megabytes. A remote, unauthenticated attacker, along with conditions beyond their control, could send large headers while creating an upstream request. This may cause a heap-based buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Title NGINX ngx_http_proxy_v2_module and ngx_http_grpc_module vulnerability
Weaknesses CWE-122
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: f5

Published:

Updated: 2026-07-28T12:04:38.243Z

Reserved: 2026-06-02T21:45:04.818Z

Link: CVE-2026-42055

cve-icon Vulnrichment

Updated: 2026-07-28T12:04:38.243Z

cve-icon NVD

Status : Analyzed

Published: 2026-06-17T15:16:50.353

Modified: 2026-08-11T15:12:52.787

Link: CVE-2026-42055

cve-icon Redhat

Severity : Important

Publid Date: 2026-06-17T14:04:32Z

Links: CVE-2026-42055 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T02:15:17Z