Описание
When NGINX Plus or NGINX Open Source are configured to use the HTTP/3 QUIC module, an attacker may be able to spoof their source IP address allowing for bypass of authorization or bypass of rate limiting. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
A flaw was found in NGINX Plus and NGINX Open Source when configured to use the HTTP/3 QUIC module. A remote attacker could exploit this by spoofing their source IP address. This vulnerability allows for the bypass of authorization controls or rate limiting mechanisms, potentially leading to unauthorized access or resource abuse.
Меры по смягчению последствий
To mitigate this issue, if the HTTP/3 QUIC module is not required, disable it in your NGINX configuration. This typically involves removing or commenting out the quic parameter from listen directives in your nginx.conf file. After modifying the configuration, a graceful reload or restart of the NGINX service is required for the changes to take effect. For example, use sudo systemctl reload nginx or sudo systemctl restart nginx.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | nginx | Fix deferred | ||
| Red Hat Enterprise Linux 8 | nginx:1.24/nginx | Fix deferred | ||
| Red Hat Enterprise Linux 9 | nginx | Fix deferred | ||
| Red Hat Enterprise Linux 9 | nginx:1.24/nginx | Out of support scope | ||
| Red Hat Enterprise Linux 9 | nginx:1.26/nginx | Out of support scope | ||
| Red Hat Hardened Images | nginx-main-1.30.2-1.hum1 | Fixed | RHSA-2026:20351 | 23.05.2026 |
Показывать по
Дополнительная информация
Статус:
EPSS
6.5 Medium
CVSS3
Связанные уязвимости
When NGINX Plus or NGINX Open Source are configured to use the HTTP/3 QUIC module, an attacker may be able to spoof their source IP address allowing for bypass of authorization or bypass of rate limiting. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
When NGINX Plus or NGINX Open Source are configured to use the HTTP/3 QUIC module, an attacker may be able to spoof their source IP address allowing for bypass of authorization or bypass of rate limiting. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
When NGINX Plus or NGINX Open Source are configured to use the HTTP/3 ...
When NGINX Plus or NGINX Open Source are configured to use the HTTP/3 QUIC module, an attacker may be able to spoof their source IP address allowing for bypass of authorization or bypass of rate limiting. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
EPSS
6.5 Medium
CVSS3