F5-K000139609: Medium severity nginx vulnerability
When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 encoder instructions can cause NGINX worker processes to terminate or cause other potential impact.
Affected Software
Event History
Frequently Asked Questions
What is the severity of F5-K000139609?
The severity of F5-K000139609 is classified as a significant vulnerability due to the potential termination of NGINX worker processes.
How do I fix F5-K000139609?
To fix F5-K000139609, update NGINX Plus to version 32 or NGINX Open Source to version 1.27.01.26.1 or later.
What software is affected by F5-K000139609?
F5-K000139609 affects both NGINX Plus version 30 and NGINX Open Source versions between 1.25.0 and 1.26.0.
What impact does F5-K000139609 have on NGINX?
F5-K000139609 can lead to unexpected terminations of NGINX worker processes, disrupting web services.
Is there a workaround for F5-K000139609?
A temporary workaround for F5-K000139609 may involve disabling the HTTP/3 QUIC module until a patch is applied.