CVE-2024-24989: NGINX HTTP/3 QUIC vulnerability
When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed requests can cause NGINX worker processes to terminate.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
NGINXto a version that resolves this vulnerability.Fixed in 31 - Upgrade
Upgrade
Nginxto a version that resolves this vulnerability.Fixed in 1.25.4 - Configuration
Do not configure NGINX to use the HTTP/3 QUIC module; if it is enabled, disable the HTTP/3 QUIC module because undisclosed requests can cause NGINX worker processes to terminate.
NGINX HTTP/3 QUIC module HTTP/3 QUIC module enabled = disable
Event History
Frequently Asked Questions
What is the severity of CVE-2024-24989?
CVE-2024-24989 has not been assigned a specific severity level but indicates potential service disruption.
How do I fix CVE-2024-24989?
To mitigate CVE-2024-24989, disable the HTTP/3 QUIC module in NGINX Plus or NGINX Open Source configurations.
Which versions are affected by CVE-2024-24989?
CVE-2024-24989 affects NGINX Plus version 31 and NGINX Open Source version 1.25.3.
What impact does CVE-2024-24989 have on NGINX?
CVE-2024-24989 can cause NGINX worker processes to terminate upon processing certain undisclosed requests.
Is the HTTP/3 QUIC module enabled by default in NGINX?
No, the HTTP/3 QUIC module is not enabled by default in NGINX and is considered experimental.