Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-40460

Опубликовано: 13 мая 2026
Источник: debian

Описание

When NGINX Plus or NGINX Open Source are configured to use the HTTP/3 QUIC module, an attacker may be able to spoof their source IP address allowing for bypass of authorization or bypass of rate limiting.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
nginxfixed1.30.0-4package
nginxfixed1.26.3-3+deb13u5trixiepackage
nginxnot-affectedbookwormpackage
nginxnot-affectedbullseyepackage

Примечания

  • https://my.f5.com/manage/s/article/K000161068

  • https://nginx.org/en/security_advisories.html

  • https://github.com/nginx/nginx/commit/5461e8bbc09230a4cf8e3d7737c176ae69b091f1 (release-1.30.1)

Связанные уязвимости

CVSS3: 6.5
ubuntu
3 месяца назад

When NGINX Plus or NGINX Open Source are configured to use the HTTP/3 QUIC module, an attacker may be able to spoof their source IP address allowing for bypass of authorization or bypass of rate limiting.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 6.5
redhat
3 месяца назад

When NGINX Plus or NGINX Open Source are configured to use the HTTP/3 QUIC module, an attacker may be able to spoof their source IP address allowing for bypass of authorization or bypass of rate limiting.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 6.5
nvd
3 месяца назад

When NGINX Plus or NGINX Open Source are configured to use the HTTP/3 QUIC module, an attacker may be able to spoof their source IP address allowing for bypass of authorization or bypass of rate limiting.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 6.5
msrc
3 месяца назад

NGINX ngx_quic_module vulnerability

CVSS3: 6.5
github
3 месяца назад

When NGINX Plus or NGINX Open Source are configured to use the HTTP/3 QUIC module, an attacker may be able to spoof their source IP address allowing for bypass of authorization or bypass of rate limiting.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.