CVE-2024-32760: NGINX HTTP/3 QUIC vulnerability
When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 encoder instructions can cause NGINX worker processes to terminate or cause or other potential impact.
Other sources
When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 encoder instructions can cause NGINX worker processes to terminate or cause other potential impact.
— F5
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-32760?
The severity of CVE-2024-32760 is currently classified as high, due to potential worker process termination in affected systems.
How do I fix CVE-2024-32760?
To fix CVE-2024-32760, upgrade NGINX Plus to version r31 or r30-p2, or NGINX Open Source to version 1.27.0 or above.
What types of software are affected by CVE-2024-32760?
CVE-2024-32760 affects specific versions of NGINX Plus and NGINX Open Source configured with the HTTP/3 QUIC module.
What impact does CVE-2024-32760 have on NGINX deployments?
CVE-2024-32760 can lead to abrupt termination of NGINX worker processes, affecting service availability.
Is there a workaround for CVE-2024-32760?
While the best solution is to apply the updates, temporarily disabling the HTTP/3 QUIC module may serve as a workaround until the update can be applied.