CVE-2026-42055

Red Hat Security Advisory: Red Hat Update Infrastructure 5.3 Technology Preview security update

criticalPoCEPSS 6.5%

Description

A flaw was found in NGINX. When NGINX is configured to proxy HTTP/2 traffic using the ngx_http_proxy_v2_module or ngx_http_grpc_module with specific settings, a remote, unauthenticated attacker can send specially crafted large headers. This can trigger a heap-based buffer overflow, leading to a restart of the NGINX worker process and a Denial of Service (DoS). Under certain conditions, such as when Address Space Layout Randomization (ASLR) is disabled or bypassed, this vulnerability could also allow for arbitrary code execution.

Metrics

Severity
critical
PoC (publicly reported)
9.2
Source: nvd-v4
93.4 %
Critical — this CVE ranks in the top fifth of all CVEs scored today (rank ≥ 80%).
6.5 %
Moderate — model estimates 1-10% exploitation likelihood.
Published
2026-08-24 11:15 UTC
CWE-122

Weakness classes (CWE)

  • CWE-122Variant

    Heap-based Buffer Overflow

    A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

    cwe.mitre.org →

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. CVE Modified2026-08-25 13:19 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Reference: https://access.redhat.com/errata/RHSA-2026:58981
    • Affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9 (+10)Red Hat Openshift Data Foundation 4, Red Hat Discovery 2, Red Hat Update Infrastructure 5 (+7)
  2. Reanalysis2026-08-11 15:12 UTC· nvd@nist.gov
    • CPE Configuration: OR *cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:* *cpe:2.3:a:redhat:discovery:-:*:*:*:*:*:*:* *cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:* *cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:* *cpe:2.3:a:redhat:hardened_images:-:*:*:*:*:*:*:* *cpe:2.3:a:redhat:update_infrastructure:*:*:*:*:*:*:*:* versions from (including) 5.0 up to (excluding) 5.2
    • CPE Configuration: OR *cpe:2.3:a:f5:nginx_plus:r30:-:*:*:*:*:*:* *cpe:2.3:a:f5:nginx_plus:r31:p1:*:*:*:*:*:* *cpe:2.3:a:f5:nginx_plus:r30:p2:*:*:*:*:*:* *cpe:2.3:a:f5:nginx_plus:r31:-:*:*:*:*:*:* *cpe:2.3:a:f5:nginx_plus:r32:-:*:*:*:*:*:* *cpe:2.3:a:f5:nginx_plus:r30:p1:*:*:*:*:*:* *cpe:2.3:a:f5:nginx_plus:r32:p1:*:*:*:*:*:* *cpe:2.3:a:f5:nginx_plus:r32:p2:*:*:*:*:*:* *cpe:2.3:a:f5:nginx_plus:r33:-:*:*:*:*:*:* *cpe:2.3:a:f5:nginx_plus:r33:p1:*:*:*:*:*:* *cpe:2.3:a:f5:nginx_plus:r33:p2:*:*:*:*:*:* *cpe:2.3:a:f5:nginx_plus:r34:-:*:*:*:*:*:* *cpe:2.3:a:f5:nginx_plus:r34:p1:*:*:*:*:*:* *cpe:2.3:a:f5:nginx_plus:r32:p3:*:*:*:*:*:* *cpe:2.3:a:f5:nginx_plus:r33:p3:*:*:*:*:*:* *cpe:2.3:a:f5:nginx_plus:r34:p2:*:*:*:*:*:* *cpe:2.3:a:f5:nginx_plus:r35:-:*:*:*:*:*:* *cpe:2.3:a:f5:nginx_plus:r36:-:*:*:*:*:*:* *cpe:2.3:a:f5:nginx_plus:r36:p1:*:*:*:*:*:* *cpe:2.3:a:f5:nginx_plus:r35:p1:*:*:*:*:*:* *cpe:2.3:a:f5:nginx_plus:r36:p2:*:*:*:*:*:* *cpe:2.3:a:f5:nginx_plus:r32:p4:*:*:*:*:*:* *cpe:2.3:a:f5:nginx_gateway_fabric:*:*:*:*:*:*:*:* versions from (including) 1.3.0 up to (including) 1.6.2 *cpe:2.3:a:f5:nginx_ingress_controller:*:*:*:*:*:*:*:* versions from (including) 3.5.0 up to (including) 3.7.2 *cpe:2.3:a:f5:dos:*:*:*:*:*:nginx:*:* versions from (including) 4.3.0 up to (including) 4.7.0 *cpe:2.3:a:f5:dos:4.9.0:*:*:*:*:nginx:*:* *cpe:2.3:a:f5:nginx_instance_manager:*:*:*:*:*:*:*:* versions from (including) 2.17.0 up to (including) 2.22.0 *cpe:2.3:a:f5:nginx_plus:*:*:*:*:*:*:*:* versions from (including) 37.0.0 up to (including) 37.0.1 *cpe:2.3:a:f5:waf:*:*:*:*:*:nginx:*:* versions from (including) 4.10.0 up to (including) 4.16.0 *cpe:2.3:a:f5:waf:*:*:*:*:*:nginx:*:* versions from (including) 5.2.0 up to (including) 5.8.0 *cpe:2.3:a:f5:waf:*:*:*:*:*:nginx:*:* versions from (including) 5.9.0 up to (including) 5.13.1 *cpe:2.3:a:f5:nginx_gateway_fabric:*:*:*:*:*:*:*:* versions from (including) 2.0.0 up to (excluding) 2.6.4 *cpe:2.3:a:f5:nginx_ingress_controller:*:*:*:*:*:*:*:* versions from (including) 5.0.0 up to (excluding) 5.5.1 *cpe:2.3:a:f5:nginx_ingress_controller:4.0.0:*:*:*:*:*:*:* *cpe:2.3:a:f5:nginx_ingress_controller:4.0.1:*:*:*:*:*:*:* *cpe:2.3:a:f5:nginx_open_source:*:*:*:*:*:*:*:* versions from (including) 1.30.0 up to (excluding) 1.30.3 *cpe:2.3:a:f5:nginx_open_source:1.31.1:*:*:*:*:*:*:* *cpe:2.3:a:f5:nginx_plus:r3:*:*:*:*:*:*:* *cpe:2.3:a:f5:nginx_plus:r31:p2:*:*:*:*:*:* *cpe:2.3:a:f5:nginx_plus:r31:p3:*:*:*:*:*:* *cpe:2.3:a:f5:nginx_plus:r36:p3:*:*:*:*:*:* *cpe:2.3:a:f5:nginx_plus:r36:p4:*:*:*:*:*:* *cpe:2.3:a:f5:nginx_plus:r36:p5:*:*:*:*:*:* *cpe:2.3:a:f5:waf:4.8.1:*:*:*:*:nginx:*:*OR *cpe:2.3:a:f5:nginx_gateway_fabric:*:*:*:*:*:*:*:* versions from (including) 1.3.0 up to (including) 1.6.2 *cpe:2.3:a:f5:dos:*:*:*:*:*:nginx:*:* versions from (including) 4.3.0 up to (including) 4.7.0 *cpe:2.3:a:f5:dos:4.9.0:*:*:*:*:nginx:*:* *cpe:2.3:a:f5:nginx_gateway_fabric:*:*:*:*:*:*:*:* versions from (including) 2.0.0 up to (including) 2.6.3 *cpe:2.3:a:f5:nginx_instance_manager:*:*:*:*:*:*:*:* versions from (including) 2.17.0 up to (including) 2.22.0 *cpe:2.3:a:f5:nginx_open_source:*:*:*:*:*:*:*:* versions from (including) 1.0.0 up to (including) 1.30.2 *cpe:2.3:a:f5:nginx_open_source:*:*:*:*:*:*:*:* versions from (including) 1.31.0 up to (including) 1.31.1 *cpe:2.3:a:f5:waf:*:*:*:*:*:nginx:*:* versions from (including) 4.10.0 up to (including) 4.16.0 *cpe:2.3:a:f5:waf:*:*:*:*:*:nginx:*:* versions from (including) 5.2.0 up to (including) 5.8.0 *cpe:2.3:a:f5:waf:*:*:*:*:*:nginx:*:* versions from (including) 5.9.0 up to (including) 5.13.1 *cpe:2.3:a:f5:nginx_ingress_controller:*:*:*:*:continuous_releases:*:*:* versions from (including) 3.5.0 up to (including) 3.7.2 *cpe:2.3:a:f5:nginx_plus:*:*:*:*:continuous_releases:*:*:* versions from (including) r33 up to (excluding) r36 *cpe:2.3:a:f5:nginx_plus:r36:-:*:*:continuous_releases:*:*:* *cpe:2.3:a:f5:nginx_plus:r36:p1:*:*:continuous_releases:*:*:* *cpe:2.3:a:f5:nginx_plus:r36:p2:*:*:continuous_releases:*:*:* *cpe:2.3:a:f5:nginx_plus:r36:p3:*:*:continuous_releases:*:*:* *cpe:2.3:a:f5:nginx_plus:r36:p4:*:*:continuous_releases:*:*:* *cpe:2.3:a:f5:nginx_ingress_controller:*:*:*:*:continuous_releases:*:*:* versions from (including) 4.0.0 up to (including) 4.0.1 *cpe:2.3:a:f5:nginx_plus:*:*:*:*:long-term_support:*:*:* versions from (including) 37.0.0.1 up to (excluding) 37.0.2.1 *cpe:2.3:a:f5:nginx_plus:r36:p5:*:*:continuous_releases:*:*:* *cpe:2.3:a:f5:nginx_ingress_controller:*:*:*:*:continuous_releases:*:*:* versions from (including) 5.0.0 up to (including) 5.5.0
    • Reference Type: redhat-SADP: https://bugzilla.redhat.com/show_bug.cgi?id=2489866 Types: Third Party Advisoryredhat-SADP: https://bugzilla.redhat.com/show_bug.cgi?id=2489866 Types: Issue Tracking, Third Party Advisory
  3. Modified Analysis2026-08-10 15:39 UTC· nvd@nist.gov
    • CPE Configuration: OR *cpe:2.3:a:f5:nginx_plus:r30:-:*:*:*:*:*:* *cpe:2.3:a:f5:nginx_plus:r31:p1:*:*:*:*:*:* *cpe:2.3:a:f5:nginx_plus:r30:p2:*:*:*:*:*:* *cpe:2.3:a:f5:nginx_plus:r31:-:*:*:*:*:*:* *cpe:2.3:a:f5:nginx_plus:r32:-:*:*:*:*:*:* *cpe:2.3:a:f5:nginx_plus:r30:p1:*:*:*:*:*:* *cpe:2.3:a:f5:nginx_plus:r32:p1:*:*:*:*:*:* *cpe:2.3:a:f5:nginx_plus:r32:p2:*:*:*:*:*:* *cpe:2.3:a:f5:nginx_plus:r33:-:*:*:*:*:*:* *cpe:2.3:a:f5:nginx_plus:r33:p1:*:*:*:*:*:* *cpe:2.3:a:f5:nginx_plus:r33:p2:*:*:*:*:*:* *cpe:2.3:a:f5:nginx_plus:r34:-:*:*:*:*:*:* *cpe:2.3:a:f5:nginx_plus:r34:p1:*:*:*:*:*:* *cpe:2.3:a:f5:nginx_plus:r32:p3:*:*:*:*:*:* *cpe:2.3:a:f5:nginx_plus:r33:p3:*:*:*:*:*:* *cpe:2.3:a:f5:nginx_plus:r34:p2:*:*:*:*:*:* *cpe:2.3:a:f5:nginx_plus:r35:-:*:*:*:*:*:* *cpe:2.3:a:f5:nginx_plus:r36:-:*:*:*:*:*:* *cpe:2.3:a:f5:nginx_plus:r36:p1:*:*:*:*:*:* *cpe:2.3:a:f5:nginx_plus:r35:p1:*:*:*:*:*:* *cpe:2.3:a:f5:nginx_plus:r36:p2:*:*:*:*:*:* *cpe:2.3:a:f5:nginx_plus:r32:p4:*:*:*:*:*:* *cpe:2.3:a:f5:nginx_app_protect_dos:*:*:*:*:*:*:*:* versions from (including) 4.3.0 up to (including) 4.7.0 *cpe:2.3:a:f5:nginx_gateway_fabric:*:*:*:*:*:*:*:* versions from (including) 1.3.0 up to (including) 1.6.2 *cpe:2.3:a:f5:nginx_ingress_controller:*:*:*:*:*:*:*:* versions from (including) 3.5.0 up to (including) 3.7.2 *cpe:2.3:a:f5:dos:4.9.0:*:*:*:*:nginx:*:* *cpe:2.3:a:f5:nginx_instance_manager:*:*:*:*:*:*:*:* versions from (including) 2.17.0 up to (including) 2.22.0 *cpe:2.3:a:f5:nginx_plus:*:*:*:*:*:*:*:* versions from (including) 37.0.0 up to (including) 37.0.1 *cpe:2.3:a:f5:waf:*:*:*:*:*:nginx:*:* versions from (including) 5.9.0 up to (including) 5.13.1 *cpe:2.3:a:f5:nginx_gateway_fabric:*:*:*:*:*:*:*:* versions from (including) 2.0.0 up to (excluding) 2.6.4 *cpe:2.3:a:f5:nginx_ingress_controller:*:*:*:*:*:*:*:* versions from (including) 5.0.0 up to (excluding) 5.5.1 *cpe:2.3:a:f5:nginx_ingress_controller:4.0.0:*:*:*:*:*:*:* *cpe:2.3:a:f5:nginx_ingress_controller:4.0.1:*:*:*:*:*:*:* *cpe:2.3:a:f5:nginx_app_protect_waf:*:*:*:*:*:*:*:* versions from (including) 4.10.0 up to (including) 4.16.0 *cpe:2.3:a:f5:nginx_app_protect_waf:*:*:*:*:*:*:*:* versions from (including) 5.2.0 up to (including) 5.8.0 *cpe:2.3:a:f5:nginx_open_source:*:*:*:*:*:*:*:* versions from (including) 1.30.0 up to (excluding) 1.30.3 *cpe:2.3:a:f5:nginx_open_source:1.31.1:*:*:*:*:*:*:* *cpe:2.3:a:f5:nginx_plus:r3:*:*:*:*:*:*:* *cpe:2.3:a:f5:nginx_plus:r31:p2:*:*:*:*:*:* *cpe:2.3:a:f5:nginx_plus:r31:p3:*:*:*:*:*:* *cpe:2.3:a:f5:nginx_plus:r36:p3:*:*:*:*:*:* *cpe:2.3:a:f5:nginx_plus:r36:p4:*:*:*:*:*:* *cpe:2.3:a:f5:nginx_plus:r36:p5:*:*:*:*:*:* *cpe:2.3:a:f5:waf:4.8.1:*:*:*:*:nginx:*:*OR *cpe:2.3:a:f5:nginx_plus:r30:-:*:*:*:*:*:* *cpe:2.3:a:f5:nginx_plus:r31:p1:*:*:*:*:*:* *cpe:2.3:a:f5:nginx_plus:r30:p2:*:*:*:*:*:* *cpe:2.3:a:f5:nginx_plus:r31:-:*:*:*:*:*:* *cpe:2.3:a:f5:nginx_plus:r32:-:*:*:*:*:*:* *cpe:2.3:a:f5:nginx_plus:r30:p1:*:*:*:*:*:* *cpe:2.3:a:f5:nginx_plus:r32:p1:*:*:*:*:*:* *cpe:2.3:a:f5:nginx_plus:r32:p2:*:*:*:*:*:* *cpe:2.3:a:f5:nginx_plus:r33:-:*:*:*:*:*:* *cpe:2.3:a:f5:nginx_plus:r33:p1:*:*:*:*:*:* *cpe:2.3:a:f5:nginx_plus:r33:p2:*:*:*:*:*:* *cpe:2.3:a:f5:nginx_plus:r34:-:*:*:*:*:*:* *cpe:2.3:a:f5:nginx_plus:r34:p1:*:*:*:*:*:* *cpe:2.3:a:f5:nginx_plus:r32:p3:*:*:*:*:*:* *cpe:2.3:a:f5:nginx_plus:r33:p3:*:*:*:*:*:* *cpe:2.3:a:f5:nginx_plus:r34:p2:*:*:*:*:*:* *cpe:2.3:a:f5:nginx_plus:r35:-:*:*:*:*:*:* *cpe:2.3:a:f5:nginx_plus:r36:-:*:*:*:*:*:* *cpe:2.3:a:f5:nginx_plus:r36:p1:*:*:*:*:*:* *cpe:2.3:a:f5:nginx_plus:r35:p1:*:*:*:*:*:* *cpe:2.3:a:f5:nginx_plus:r36:p2:*:*:*:*:*:* *cpe:2.3:a:f5:nginx_plus:r32:p4:*:*:*:*:*:* *cpe:2.3:a:f5:nginx_gateway_fabric:*:*:*:*:*:*:*:* versions from (including) 1.3.0 up to (including) 1.6.2 *cpe:2.3:a:f5:nginx_ingress_controller:*:*:*:*:*:*:*:* versions from (including) 3.5.0 up to (including) 3.7.2 *cpe:2.3:a:f5:dos:*:*:*:*:*:nginx:*:* versions from (including) 4.3.0 up to (including) 4.7.0 *cpe:2.3:a:f5:dos:4.9.0:*:*:*:*:nginx:*:* *cpe:2.3:a:f5:nginx_instance_manager:*:*:*:*:*:*:*:* versions from (including) 2.17.0 up to (including) 2.22.0 *cpe:2.3:a:f5:nginx_plus:*:*:*:*:*:*:*:* versions from (including) 37.0.0 up to (including) 37.0.1 *cpe:2.3:a:f5:waf:*:*:*:*:*:nginx:*:* versions from (including) 4.10.0 up to (including) 4.16.0 *cpe:2.3:a:f5:waf:*:*:*:*:*:nginx:*:* versions from (including) 5.2.0 up to (including) 5.8.0 *cpe:2.3:a:f5:waf:*:*:*:*:*:nginx:*:* versions from (including) 5.9.0 up to (including) 5.13.1 *cpe:2.3:a:f5:nginx_gateway_fabric:*:*:*:*:*:*:*:* versions from (including) 2.0.0 up to (excluding) 2.6.4 *cpe:2.3:a:f5:nginx_ingress_controller:*:*:*:*:*:*:*:* versions from (including) 5.0.0 up to (excluding) 5.5.1 *cpe:2.3:a:f5:nginx_ingress_controller:4.0.0:*:*:*:*:*:*:* *cpe:2.3:a:f5:nginx_ingress_controller:4.0.1:*:*:*:*:*:*:* *cpe:2.3:a:f5:nginx_open_source:*:*:*:*:*:*:*:* versions from (including) 1.30.0 up to (excluding) 1.30.3 *cpe:2.3:a:f5:nginx_open_source:1.31.1:*:*:*:*:*:*:* *cpe:2.3:a:f5:nginx_plus:r3:*:*:*:*:*:*:* *cpe:2.3:a:f5:nginx_plus:r31:p2:*:*:*:*:*:* *cpe:2.3:a:f5:nginx_plus:r31:p3:*:*:*:*:*:* *cpe:2.3:a:f5:nginx_plus:r36:p3:*:*:*:*:*:* *cpe:2.3:a:f5:nginx_plus:r36:p4:*:*:*:*:*:* *cpe:2.3:a:f5:nginx_plus:r36:p5:*:*:*:*:*:* *cpe:2.3:a:f5:waf:4.8.1:*:*:*:*:nginx:*:*
    • Reference Type: redhat-SADP: https://access.redhat.com/errata/RHSA-2026:36331 Types: Third Party Advisory
    • Reference Type: redhat-SADP: https://access.redhat.com/errata/RHSA-2026:36364 Types: Third Party Advisory
    • Reference Type: redhat-SADP: https://access.redhat.com/errata/RHSA-2026:36618 Types: Third Party Advisory
  4. CVE Modified2026-07-28 13:18 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Reference: https://access.redhat.com/errata/RHSA-2026:46836
    • Affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9 (+9)Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9 (+10)
  5. CVE Modified2026-07-24 13:18 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Reference: https://access.redhat.com/errata/RHSA-2026:44481
    • Affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9 (+6)Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9 (+9)

Affected operating systems

  • linux

    ubuntu / coreutilsjammy

  • linux

    ubuntu / coreutilsnoble

  • linux

    ubuntu / coreutilsresolute

  • linux

    debian / debian_linux11.0

  • linux

    redhat / enterprise_linux10.0

  • linux

    redhat / enterprise_linux10.2

  • linux

    redhat / enterprise_linux6.0

  • linux

    redhat / enterprise_linux7.0

  • linux

    redhat / enterprise_linux8.0

  • linux

    redhat / enterprise_linux9.0

  • linux

    redhat / enterprise_linux9.8

  • linux

    redhat / enterprise_linux_for_els10.2

  • linux

    redhat / enterprise_linux_for_els8.10

  • linux

    redhat / enterprise_linux_for_els9.8

  • linux

    redhat / enterprise_linux_for_eus10.2

  • linux

    redhat / enterprise_linux_for_eus9.8

  • linux

    redhat / enterprise_linux_for_ibm_z_systems10.2

  • linux

    redhat / enterprise_linux_for_ibm_z_systems8.0_s390x

  • linux

    redhat / enterprise_linux_for_ibm_z_systems9.0_s390x

  • linux

    redhat / enterprise_linux_for_ibm_z_systems_els10.2

  • linux

    redhat / enterprise_linux_for_ibm_z_systems_els8.10

  • linux

    redhat / enterprise_linux_for_ibm_z_systems_els9.8

  • linux

    redhat / enterprise_linux_for_ibm_z_systems_eus10.2

  • linux

    redhat / enterprise_linux_for_ibm_z_systems_eus9.8

Affected products

Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.

  • Apple

    iOS18.7.10

  • Apple

    iOS26.6.1

  • Apple

    iPadOS18.7.10

  • Apple

    iPadOS26.6.1

  • Apple

    macOSTahoe 26.6.2

  • bitnami

    jre1.9.0

  • bitnami

    nginx-gateway0.1.17

  • bitnami

    nginx-gateway-fabric1.3.0

  • bitnami

    postgresql15.0.0

  • bitnami

    postgresql16.0.0

  • bitnami

    postgresql17.0.0

  • bitnami

    postgresql18.0.0

  • bitnami

    python-min3.10.0

  • bitnami

    python-min3.11.0

  • bitnami

    python-min3.12.0

  • bitnami

    python-min3.13.0

  • bitnami

    python-min3.14.0

  • f5

    dos4.3.0 – 4.7.0

  • f5

    dos

  • f5

    nginx_gateway_fabric1.3.0 – 1.6.2

  • f5

    nginx_gateway_fabric2.0.0 – 2.5.1

  • f5

    nginx_ingress_controller3.5.0 – 3.7.2

  • f5

    nginx_ingress_controller4.0.0 – 4.0.1

  • f5

    nginx_ingress_controller5.0.0 – 5.4.1

References & sources

Linked CVEs

Show 93 more CVEs
IDCVE-2026-42055