CVE-2024-35200: NGINX HTTP/3 QUIC vulnerability
When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 requests can cause NGINX worker processes to terminate.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-35200?
CVE-2024-35200 is considered a critical vulnerability as it can cause NGINX worker processes to terminate when handling specific HTTP/3 requests.
How do I fix CVE-2024-35200?
To mitigate CVE-2024-35200, it is recommended to upgrade NGINX Plus to a version higher than r31-p1 and NGINX OSS to a version above 1.26.1.
What versions of NGINX are affected by CVE-2024-35200?
CVE-2024-35200 affects NGINX Plus r30, r30-p1, r30-p2, and r31, as well as NGINX OSS versions from 1.25.0 up to 1.26.1.
What configurations are impacted by CVE-2024-35200?
CVE-2024-35200 specifically impacts configurations using the HTTP/3 QUIC module in NGINX.
Can CVE-2024-35200 lead to service disruption?
Yes, CVE-2024-35200 can cause unexpected termination of NGINX worker processes, leading to possible service disruption.