F5 nginx open source是美国F5公司开源的一款高性能Web服务器和反向代理。 F5 NGINX Open Source 1.31.0版本至1.31.2之前版本存在资源管理错误漏洞,该漏洞源于ngx_http_v3_module组件中的QPACK编码器流问题,可能导致远程未认证攻击者利用特制HTTP/3会话触发释放后重用,导致工作进程重启,或在ASLR禁用或绕过时执行代码。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| F5 | NGINX Open Source | 1.31.0< 1.31.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| F5 | NGINX Open Source | 1.31.0 ~ 1.31.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-42055 | 8.1 HIGH | NGINX ngx_http_proxy_v2_module and ngx_http_grpc_module vulnerability |
| CVE-2026-11311 | 8.1 HIGH | NGINX Gateway Fabric vulnerability |
| CVE-2026-50107 | 8.1 HIGH | NGINX Gateway Fabric vulnerability |
| CVE-2026-32682 | 6.5 MEDIUM | NGINX Gateway Fabric vulnerability |
| CVE-2026-48142 | 4.8 MEDIUM | NGINX ngx_http_charset_module vulnerability |
No comments yet