Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Not in CISA KEV

CVE-2026-42055 — nginx

CVE-2026-42055 is a CWE-122 vulnerability. No vendor fix is recorded yet; mitigation options are listed below.

Also known asBIT-nginx-2026-42055BIT-nginx-gateway-2026-42055BIT-nginx-gateway-fabric-2026-42055
Published
Updated
Affected
11 products
Patched
See advisory
Exploits
None indexed
Exploitation data as of Oct 10, 2026 · OSV.dev, NVD, FIRST.org (EPSS)

Exploitation Status

No confirmed exploitation observed yet

  • A successful exploit gives an attacker total control of the affected component, not partial access.
  • CISA’s own triage has not observed active exploitation or public proof-of-concept code for this CVE as of its last assessment.

Exploitation and automatability from CISA’s SSVC triage for CVE-2026-42055.

EPSS Exploitation Probability

via FIRST.org ↗
6.5%probability of exploitation in next 30 days
Lower Risk+4.18%
Lower risk than most CVEs94th percentile — riskier than 94% of all scored CVEsHighest risk
1.10%3.33%5.56%7.79%2.9%4.0%6.5%2.4%6.5%Jul 26Sep 26Oct 26

Probability of exploitation in the next 30 days, from FIRST.org EPSS.

Description

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass directives are used to proxy HTTP/2 traffic, the ignore_invalid_headers directive is set to off, and the large_client_header_buffers directive size is larger than 2 megabytes. A remote, unauthenticated attacker, along with conditions beyond their control, could send large headers while creating an upstream request. This may cause a heap-based buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR.

Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected Products

11 products · 27 configurations
Application
dosf5
≥ 4.3.0 && ≤ 4.7.0
1 version
4.9.0
Application
nginx gateway fabricf5
≥ 2.0.0 && ≤ 2.6.3
range
Application
nginx ingress controllerf5
≥ 5.0.0 && ≤ 5.5.0
range
Application
nginx instance managerf5
≥ 2.17.0 && ≤ 2.22.0
range
Application
nginx open sourcef5
≥ 1.31.0 && ≤ 1.31.1
range
Application
nginx plusf5
≥ r33 && < r36
1 version
r36

Detection & mitigation playbook

Vulnerability
  1. Detect

    Identify every host running the affected component and compare the installed build against the fixed version below — for source-built or distro-packaged software the version string, not a lockfile, is the source of truth (`dpkg -l`, `rpm -q`, or the binary's own `--version`).

  2. Remediation status

    No fixed release is recorded for CVE-2026-42055 yet. Track the upstream advisory, and apply the exposure-reduction steps below in the meantime.

  3. Mitigate without a patch

    Stop feeding it untrusted input: reject or quarantine files and payloads from unverified sources until you can upgrade, restrict accepted formats to the ones you actually need, and run the parsing or decoding step in a least-privileged sandbox or short-lived worker so a crash or corrupted read cannot reach the rest of the process.

Fixing This On Your OS

If you run this on a Linux distribution, patch through your package manager against the distro's own security advisory below — it tracks the exact backported fix for your release, which can ship on a different timeline (and sometimes a different severity) than the upstream project.

Red HatImportant

This issue is classified as Important severity primarily because: Conditions for Exploitation: A remote, unauthenticated attacker can only exploit this if NGINX is explicitly configured to proxy HTTP/2 traffic using the ngx_http_proxy_v2_module or ngx_http_grpc_module. Impact Limitations: While the flaw reliably…

Workaround published by Red Hat
To mitigate this vulnerability, ensure that the `ignore_invalid_headers` directive is set to `on` in your NGINX configuration, or reduce the size specified by the `large_client_header_buffers` directive to 2 megabytes or less. These changes require an NGINX service reload or restart to take effect. Reloading the NGINX service is generally safe, but a restart will briefly interrupt service.
Source: Red Hat security advisory for CVE-2026-42055 (CC BY 4.0)
ProductFixed inAdvisory
Red Hat Enterprise Linux 10nginx-2:1.26.3-6.el10_2.5RHSA-2026:36364
Red Hat Enterprise Linux 8nginx:1.24-8100020260707171317.489197e6RHSA-2026:38847
Red Hat Enterprise Linux 9nginx-2:1.20.1-28.el9_8.4RHSA-2026:36331
Red Hat Enterprise Linux 9nginx:1.24-9080020260707164406.9RHSA-2026:36618
Red Hat Enterprise Linux 9nginx:1.26-9080020260707110000.9RHSA-2026:36639
Red Hat Discovery 2discovery/discovery-ui-rhel9:1784821750RHSA-2026:46836
Red Hat Hardened Imagesnginx-main-1.30.3-2.hum1RHSA-2026:27197
Red Hat Update Infrastructure 5rhui5/cds-kubernetes-rhel9:1784794818RHSA-2026:44481

Frequently Asked Questions

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass directives are used to proxy HTTP/2 traffic, the ignore_invalid_headers directive is set to off, and the large_client_header_buffers directive size is larger than 2 megabytes. A remote, unauthenticated attacker, along with conditions beyond their control, could send large headers while creating an upstream request. This may cause a heap-based buffer overflow in the NGINX worker process leading to a restar
O3 Security · Impact-Aware SCA

Is CVE-2026-42055 in your dependencies?

Find it across , including transitive dependencies.

CVE-2026-42055: nginx Memory Corruption