First published: Wed May 29 2024(Updated: )
When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 encoder instructions can cause NGINX worker processes to terminate or cause other potential impact.
Affected Software | Affected Version | How to fix |
---|---|---|
NGINX Plus | =30 | 32 |
NGINX Open Source | >=1.25.0<=1.26.0 | 1.27.01.26.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of F5-K000139609 is classified as a significant vulnerability due to the potential termination of NGINX worker processes.
To fix F5-K000139609, update NGINX Plus to version 32 or NGINX Open Source to version 1.27.01.26.1 or later.
F5-K000139609 affects both NGINX Plus version 30 and NGINX Open Source versions between 1.25.0 and 1.26.0.
F5-K000139609 can lead to unexpected terminations of NGINX worker processes, disrupting web services.
A temporary workaround for F5-K000139609 may involve disabling the HTTP/3 QUIC module until a patch is applied.