First published: Wed May 29 2024(Updated: )
When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 requests can cause NGINX worker processes to terminate or cause other potential impact. This attack requires that a request be specifically timed during the connection draining process, which the attacker has no visibility and limited influence over.
Affected Software | Affected Version | How to fix |
---|---|---|
NGINX Plus | =30 | 32 |
NGINX Open Source | >=1.25.0<=1.26.0 | 1.27.01.26.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of F5-K000139611 is not explicitly stated, but it involves worker process termination which can impact service availability.
To fix F5-K000139611, update NGINX Plus to version 30 or later, or upgrade NGINX Open Source to version 1.27.01.26.1 or later.
F5-K000139611 affects NGINX Plus version 30 and NGINX Open Source versions 1.25.0 to 1.26.0.
An attacker can cause NGINX worker processes to terminate, potentially leading to service disruption.
There is no specific workaround mentioned for F5-K000139611; the recommended action is to update the affected software.