Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

fstec логотип

BDU:2026-08509

Опубликовано: 17 июн. 2026
Источник: fstec
CVSS3: 8.1
CVSS2: 7.6
EPSS Низкий

Описание

Уязвимость модуля ngx_http_v3_module HTTP-сервера NGINX Open Source, платформы мониторинга и управления приложениями NGINX Ingress Controller, контроллера веб-сервера NGINX Gateway Fabric, платформы автоматизации NGINX Instance Manager связана с возможностью использования памяти после освобождения. Эксплуатация уязвимости может позволить нарушителю, действующему удаленно, обойти ограничения безопасности, выполнить произвольный код или вызвать отказ в обслуживании

Вендор

NGINX Inc.

Наименование ПО

NGINX Gateway Fabric
NGINX Ingress Controller
NGINX Instance Manager
NGINX Open Source

Версия ПО

от 1.3.0 до 1.6.2 включительно (NGINX Gateway Fabric)
от 4.0.0 до 4.0.1 включительно (NGINX Ingress Controller)
от 3.5.0 до 3.7.2 включительно (NGINX Ingress Controller)
от 2.17.0 до 2.22.0 включительно (NGINX Instance Manager)
от 1.31.0 до 1.31.2 (NGINX Open Source)
от 2.0.0 до 2.6.4 (NGINX Gateway Fabric)
от 5.0.0 до 5.5.1 (NGINX Ingress Controller)

Тип ПО

Прикладное ПО информационных систем
Сетевое программное средство
Сетевое средство

Операционные системы и аппаратные платформы

-

Уровень опасности уязвимости

Высокий уровень опасности (базовая оценка CVSS 2.0 составляет 7,6)
Высокий уровень опасности (базовая оценка CVSS 3.1 составляет 8,1)
Критический уровень опасности (оценка CVSS 4.0 составляет 9,2)

Возможные меры по устранению уязвимости

Использование рекомендаций производителя:
https://my.f5.com/manage/s/article/K000161616

Статус уязвимости

Подтверждена производителем

Наличие эксплойта

Существует в открытом доступе

Информация об устранении

Уязвимость устранена

Идентификаторы других систем описаний уязвимостей

EPSS

Процентиль: 87%
0.03225
Низкий

8.1 High

CVSS3

7.6 High

CVSS2

Связанные уязвимости

CVSS3: 8.1
ubuntu
около 1 месяца назад

NGINX Open Source has a vulnerability in the ngx_http_v3_module module. When NGINX Open Source is configured to use the HTTP/3 QUIC module, a remote unauthenticated attacker along with conditions beyond their control can use a specially crafted HTTP/3 session to reopen a QPACK encoder stream. This may cause a Use-after-Free in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 8.1
redhat
около 1 месяца назад

NGINX Open Source has a vulnerability in the ngx_http_v3_module module. When NGINX Open Source is configured to use the HTTP/3 QUIC module, a remote unauthenticated attacker along with conditions beyond their control can use a specially crafted HTTP/3 session to reopen a QPACK encoder stream. This may cause a Use-after-Free in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 8.1
nvd
около 1 месяца назад

NGINX Open Source has a vulnerability in the ngx_http_v3_module module. When NGINX Open Source is configured to use the HTTP/3 QUIC module, a remote unauthenticated attacker along with conditions beyond their control can use a specially crafted HTTP/3 session to reopen a QPACK encoder stream. This may cause a Use-after-Free in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 8.1
debian
около 1 месяца назад

NGINX Open Source has a vulnerability in the ngx_http_v3_modulemodule. ...

CVSS3: 8.1
github
около 1 месяца назад

NGINX Open Source has a vulnerability in the ngx_http_v3_module module. When NGINX Open Source is configured to use the HTTP/3 QUIC module, a remote unauthenticated attacker along with conditions beyond their control can use a specially crafted HTTP/3 session to reopen a QPACK encoder stream. This may cause a Use-after-Free in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

EPSS

Процентиль: 87%
0.03225
Низкий

8.1 High

CVSS3

7.6 High

CVSS2