F5 Nginx是美国F5公司的一款轻量级Web服务器/反向代理服务器及电子邮件(IMAP/POP3)代理服务器,在BSD-like协议下发行。 F5 Nginx Plus R30 到 R31、NGINX Open Source 1.25.0 到 1.26.0版本存在安全漏洞,该漏洞源于当NGINX OSS 配置为使用 HTTP/3 QUIC 模块时,未公开的 HTTP/3 编码器指令可能会导致 NGINX 工作进程终止或其他影响。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| F5 | NGINX Open Source | 1.25.0 ~ 1.26.1 | - |
|
| F5 | NGINX Plus | R30 ~ R32 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-34161 | 5.3 MEDIUM | NGINX HTTP/3 QUIC vulnerability |
| CVE-2024-35200 | 5.3 MEDIUM | NGINX HTTP/3 QUIC vulnerability |
| CVE-2024-31079 | 4.8 MEDIUM | NGINX HTTP/3 QUIC vulnerability |
No comments yet