Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-40460

Опубликовано: 13 мая 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

When NGINX Plus or NGINX Open Source are configured to use the HTTP/3 QUIC module, an attacker may be able to spoof their source IP address allowing for bypass of authorization or bypass of rate limiting.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

A flaw was found in NGINX Plus and NGINX Open Source when configured to use the HTTP/3 QUIC module. A remote attacker could exploit this by spoofing their source IP address. This vulnerability allows for the bypass of authorization controls or rate limiting mechanisms, potentially leading to unauthorized access or resource abuse.

Меры по смягчению последствий

To mitigate this issue, if the HTTP/3 QUIC module is not required, disable it in your NGINX configuration. This typically involves removing or commenting out the quic parameter from listen directives in your nginx.conf file. After modifying the configuration, a graceful reload or restart of the NGINX service is required for the changes to take effect. For example, use sudo systemctl reload nginx or sudo systemctl restart nginx.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10nginxFix deferred
Red Hat Enterprise Linux 8nginx:1.24/nginxFix deferred
Red Hat Enterprise Linux 9nginxFix deferred
Red Hat Enterprise Linux 9nginx:1.24/nginxOut of support scope
Red Hat Enterprise Linux 9nginx:1.26/nginxOut of support scope
Red Hat Hardened Imagesnginx-main-1.30.2-1.hum1FixedRHSA-2026:2035123.05.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-290
https://bugzilla.redhat.com/show_bug.cgi?id=2477113nginx: NGINX: Authorization bypass via IP spoofing in HTTP/3 QUIC module

EPSS

Процентиль: 29%
0.00367
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
3 месяца назад

When NGINX Plus or NGINX Open Source are configured to use the HTTP/3 QUIC module, an attacker may be able to spoof their source IP address allowing for bypass of authorization or bypass of rate limiting.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 6.5
nvd
3 месяца назад

When NGINX Plus or NGINX Open Source are configured to use the HTTP/3 QUIC module, an attacker may be able to spoof their source IP address allowing for bypass of authorization or bypass of rate limiting.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 6.5
msrc
3 месяца назад

NGINX ngx_quic_module vulnerability

CVSS3: 6.5
debian
3 месяца назад

When NGINX Plus or NGINX Open Source are configured to use the HTTP/3 ...

CVSS3: 6.5
github
3 месяца назад

When NGINX Plus or NGINX Open Source are configured to use the HTTP/3 QUIC module, an attacker may be able to spoof their source IP address allowing for bypass of authorization or bypass of rate limiting.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

EPSS

Процентиль: 29%
0.00367
Низкий

6.5 Medium

CVSS3