Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-40460

Опубликовано: 13 мая 2026
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

When NGINX Plus or NGINX Open Source are configured to use the HTTP/3 QUIC module, an attacker may be able to spoof their source IP address allowing for bypass of authorization or bypass of rate limiting.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:f5:dos:*:*:*:*:*:nginx:*:*
Версия от 4.3.0 (включая) до 4.7.0 (включая)
cpe:2.3:a:f5:dos:4.8.0:*:*:*:*:nginx:*:*
cpe:2.3:a:f5:nginx_gateway_fabric:*:*:*:*:*:*:*:*
Версия от 1.3.0 (включая) до 1.6.2 (включая)
cpe:2.3:a:f5:nginx_gateway_fabric:*:*:*:*:*:*:*:*
Версия от 2.0.0 (включая) до 2.6.0 (включая)
cpe:2.3:a:f5:nginx_ingress_controller:*:*:*:*:*:*:*:*
Версия от 3.5.0 (включая) до 3.7.2 (включая)
cpe:2.3:a:f5:nginx_ingress_controller:*:*:*:*:*:*:*:*
Версия от 4.0.0 (включая) до 4.0.1 (включая)
cpe:2.3:a:f5:nginx_ingress_controller:*:*:*:*:*:*:*:*
Версия от 5.0.0 (включая) до 5.4.2 (включая)
cpe:2.3:a:f5:nginx_instance_manager:*:*:*:*:*:*:*:*
Версия от 2.16.0 (включая) до 2.22.0 (включая)
cpe:2.3:a:f5:nginx_open_source:*:*:*:*:*:*:*:*
Версия от 1.25.0 (включая) до 1.30.0 (включая)
cpe:2.3:a:f5:nginx_plus:*:*:*:*:*:*:*:*
Версия от r32 (включая) до r36 (включая)
cpe:2.3:a:f5:waf:*:*:*:*:*:nginx:*:*
Версия от 4.9.0 (включая) до 4.16.0 (включая)
cpe:2.3:a:f5:waf:*:*:*:*:*:nginx:*:*
Версия от 5.1.0 (включая) до 5.8.0 (включая)
cpe:2.3:a:f5:waf:*:*:*:*:*:nginx:*:*
Версия от 5.9.0 (включая) до 5.12.1 (включая)

EPSS

Процентиль: 29%
0.00367
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-290

Связанные уязвимости

CVSS3: 6.5
ubuntu
3 месяца назад

When NGINX Plus or NGINX Open Source are configured to use the HTTP/3 QUIC module, an attacker may be able to spoof their source IP address allowing for bypass of authorization or bypass of rate limiting.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 6.5
redhat
3 месяца назад

When NGINX Plus or NGINX Open Source are configured to use the HTTP/3 QUIC module, an attacker may be able to spoof their source IP address allowing for bypass of authorization or bypass of rate limiting.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 6.5
msrc
3 месяца назад

NGINX ngx_quic_module vulnerability

CVSS3: 6.5
debian
3 месяца назад

When NGINX Plus or NGINX Open Source are configured to use the HTTP/3 ...

CVSS3: 6.5
github
3 месяца назад

When NGINX Plus or NGINX Open Source are configured to use the HTTP/3 QUIC module, an attacker may be able to spoof their source IP address allowing for bypass of authorization or bypass of rate limiting.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

EPSS

Процентиль: 29%
0.00367
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-290