CVE-2026-42055: NGINX ngx_http_proxy_v2_module and ngx_http_grpc_module vulnerability

Published Jun 17, 2026
·
Updated

NGINX ngxhttpproxyv2module and ngxhttpgrpcmodule vulnerability

Other sources

NGINX Plus and NGINX Open Source have a vulnerability in the ngxhttpproxyv2module and ngxhttpgrpcmodule modules. This vulnerability exists when the proxyhttpversion to 2 or grpcpass directives are used to proxy HTTP/2 traffic, the ignoreinvalidheaders directive is set to off, and the largeclientheaderbuffers directive size is larger than 2 megabytes. A remote, unauthenticated attacker, along with conditions beyond their control, could send large headers while creating an upstream request. This may cause a heap-based buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR.

Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Red Hat

Affected Software

30 affected componentsFixes available
Nginx Plus
Nginx Open Source
Microsoft azl3 nginx 1.28.3-6<1.28.3-7
1.28.3-7
F5 Dos Nginx>=4.3.0<=4.7.0
F5 Dos Nginx=4.9.0
F5 NGINX Gateway Fabric>=1.3.0<=1.6.2
F5 NGINX Gateway Fabric>=2.0.0<=2.6.3
F5 NGINX Ingress Controller>=3.5.0<=3.7.2
F5 NGINX Ingress Controller>=4.0.0<=4.0.1
F5 NGINX Ingress Controller>=5.0.0<=5.5.0
F5 NGINX Instance Manager>=2.17.0<=2.22.0
F5 NGINX Open Source>=1.0.0<=1.30.2
F5 NGINX Open Source>=1.31.0<=1.31.1
F5 NGINX Plus>=37.0.0.1<37.0.2.1
F5 NGINX Plus>=r33<r36
F5 NGINX Plus=r36
F5 NGINX Plus=r36-p1
F5 NGINX Plus=r36-p2
F5 NGINX Plus=r36-p3
F5 NGINX Plus=r36-p4
F5 NGINX Plus=r36-p5
F5 Waf Nginx>=4.10.0<=4.16.0
F5 Waf Nginx>=5.2.0<=5.8.0
F5 Waf Nginx>=5.9.0<=5.13.1
redhat Discovery
redhat Hardened Images
redhat Update Infrastructure>=5.0<5.2
redhat Enterprise Linux=8.0
redhat Enterprise Linux=9.0
redhat Enterprise Linux=10.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 1.28.3-7
  2. Configuration

    Set the ignore_invalid_headers directive to an appropriate value to avoid the vulnerable condition where ignore_invalid_headers is set to off (required for the heap-based buffer overflow trigger described for ngx_http_proxy_v2_module and ngx_http_grpc_module).

    NGINX ngx_http_proxy_v2_module / ngx_http_grpc_module ignore_invalid_headers = off
  3. Configuration

    Reduce the large_client_header_buffers directive size so it is not larger than 2 megabytes, since the vulnerability exists when large_client_header_buffers is larger than 2 megabytes.

    NGINX ngx_http_proxy_v2_module / ngx_http_grpc_module large_client_header_buffers = <= 2 megabytes

Event History

Jun 17, 2026
CVE Published
via MITRE·02:04 PM
Data Sourced
via MITRE·02:04 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeaknessAffected Software
Data Sourced
via Red Hat·04:02 PM
DescriptionSeverityAffected Software
Jun 18, 2026
News Published
via BleepingComputer·11:33 AM
News Published
via BleepingComputer·11:35 AM
Jul 1, 2026
Data Sourced
via Microsoft·08:01 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·08:01 AM
Affected Software
Updated
via Microsoft·08:01 AM
DescriptionSeverity
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-42055?

The severity of CVE-2026-42055 is critical with a CVSS score of 9.2.

2

What systems are affected by CVE-2026-42055?

CVE-2026-42055 affects NGINX Plus and NGINX Open Source when using ngx_http_proxy_v2_module and ngx_http_grpc_module.

3

How do I fix CVE-2026-42055?

To fix CVE-2026-42055, apply the latest patches provided by NGINX for the affected modules.

4

What type of vulnerability is CVE-2026-42055?

CVE-2026-42055 is classified as a buffer overflow vulnerability.

5

What configurations trigger CVE-2026-42055?

CVE-2026-42055 is triggered when proxy_http_version is set to 2 or grpc_pass directives are used with the ignore_invalid_headers directive set to off.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203