CVE-2026-42055 — nginx
CVE-2026-42055 is a CWE-122 vulnerability. No vendor fix is recorded yet; mitigation options are listed below.
Exploitation Status
No confirmed exploitation observed yet
- A successful exploit gives an attacker total control of the affected component, not partial access.
- CISA’s own triage has not observed active exploitation or public proof-of-concept code for this CVE as of its last assessment.
Exploitation and automatability from CISA’s SSVC triage for CVE-2026-42055.
EPSS Exploitation Probability
Probability of exploitation in the next 30 days, from FIRST.org EPSS.
Description
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass directives are used to proxy HTTP/2 traffic, the ignore_invalid_headers directive is set to off, and the large_client_header_buffers directive size is larger than 2 megabytes. A remote, unauthenticated attacker, along with conditions beyond their control, could send large headers while creating an upstream request. This may cause a heap-based buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected Products
dosf5nginx gateway fabricf5nginx ingress controllerf5nginx instance managerf5nginx open sourcef5nginx plusf5Detection & mitigation playbook
VulnerabilityDetect
Identify every host running the affected component and compare the installed build against the fixed version below — for source-built or distro-packaged software the version string, not a lockfile, is the source of truth (`dpkg -l`, `rpm -q`, or the binary's own `--version`).
Remediation status
No fixed release is recorded for CVE-2026-42055 yet. Track the upstream advisory, and apply the exposure-reduction steps below in the meantime.
Mitigate without a patch
Stop feeding it untrusted input: reject or quarantine files and payloads from unverified sources until you can upgrade, restrict accepted formats to the ones you actually need, and run the parsing or decoding step in a least-privileged sandbox or short-lived worker so a crash or corrupted read cannot reach the rest of the process.
Fixing This On Your OS
If you run this on a Linux distribution, patch through your package manager against the distro's own security advisory below — it tracks the exact backported fix for your release, which can ship on a different timeline (and sometimes a different severity) than the upstream project.
This issue is classified as Important severity primarily because: Conditions for Exploitation: A remote, unauthenticated attacker can only exploit this if NGINX is explicitly configured to proxy HTTP/2 traffic using the ngx_http_proxy_v2_module or ngx_http_grpc_module. Impact Limitations: While the flaw reliably…
To mitigate this vulnerability, ensure that the `ignore_invalid_headers` directive is set to `on` in your NGINX configuration, or reduce the size specified by the `large_client_header_buffers` directive to 2 megabytes or less. These changes require an NGINX service reload or restart to take effect. Reloading the NGINX service is generally safe, but a restart will briefly interrupt service.Source: Red Hat security advisory for CVE-2026-42055 (CC BY 4.0)
| Product | Fixed in | Advisory |
|---|---|---|
| Red Hat Enterprise Linux 10 | nginx-2:1.26.3-6.el10_2.5 | RHSA-2026:36364 |
| Red Hat Enterprise Linux 8 | nginx:1.24-8100020260707171317.489197e6 | RHSA-2026:38847 |
| Red Hat Enterprise Linux 9 | nginx-2:1.20.1-28.el9_8.4 | RHSA-2026:36331 |
| Red Hat Enterprise Linux 9 | nginx:1.24-9080020260707164406.9 | RHSA-2026:36618 |
| Red Hat Enterprise Linux 9 | nginx:1.26-9080020260707110000.9 | RHSA-2026:36639 |
| Red Hat Discovery 2 | discovery/discovery-ui-rhel9:1784821750 | RHSA-2026:46836 |
| Red Hat Hardened Images | nginx-main-1.30.3-2.hum1 | RHSA-2026:27197 |
| Red Hat Update Infrastructure 5 | rhui5/cds-kubernetes-rhel9:1784794818 | RHSA-2026:44481 |
Frequently Asked Questions
Is CVE-2026-42055 in your dependencies?
Find it across , including transitive dependencies.