F5-K000139611: Medium severity nginx vulnerability
When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 requests can cause NGINX worker processes to terminate or cause other potential impact. This attack requires that a request be specifically timed during the connection draining process, which the attacker has no visibility and limited influence over.
Affected Software
Event History
Frequently Asked Questions
What is the severity of F5-K000139611?
The severity of F5-K000139611 is not explicitly stated, but it involves worker process termination which can impact service availability.
How do I fix F5-K000139611?
To fix F5-K000139611, update NGINX Plus to version 30 or later, or upgrade NGINX Open Source to version 1.27.01.26.1 or later.
What products are affected by F5-K000139611?
F5-K000139611 affects NGINX Plus version 30 and NGINX Open Source versions 1.25.0 to 1.26.0.
What can an attacker gain from exploiting F5-K000139611?
An attacker can cause NGINX worker processes to terminate, potentially leading to service disruption.
Is there a workaround for F5-K000139611?
There is no specific workaround mentioned for F5-K000139611; the recommended action is to update the affected software.