First published: Wed May 29 2024(Updated: )
When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 requests can cause NGINX worker processes to terminate or cause other potential impact. This attack requires that a request be specifically timed during the connection draining process, which the attacker has no visibility and limited influence over.
Affected Software | Affected Version | How to fix |
---|---|---|
F5 NGINX Plus | =30 | 32 |
F5 NGINX Open Source | >=1.25.0<=1.26.0 | 1.27.01.26.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.