{"id":"CVE-2026-42055","aliases":["BIT-nginx-2026-42055","BIT-nginx-gateway-2026-42055","BIT-nginx-gateway-fabric-2026-42055"],"url":"https://o3.security/vulnerability/CVE-2026-42055","summary":null,"details":"NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass directives are used to proxy HTTP/2 traffic, the ignore_invalid_headers directive is set to off, and the large_client_header_buffers directive size is larger than 2 megabytes. A remote, unauthenticated attacker, along with conditions beyond their control, could send large headers while creating an upstream request. This may cause a heap-based buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. \n\n\nNote: Software versions which have reached End of Technical Support (EoTS) are not evaluated.","published":"2026-06-17T15:16:50.353Z","modified":"2026-08-13T04:02:52.959063476Z","cvss":null,"epss":{"score":0.04022,"percentile":0.89785,"asOf":"2026-08-24"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[],"fix":null,"references":[{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:27197"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:36331"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:36364"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:36618"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:36639"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:38847"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:44481"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:46836"},{"type":"ADVISORY","url":"https://access.redhat.com/security/cve/CVE-2026-42055"},{"type":"ADVISORY","url":"https://my.f5.com/manage/s/article/K000161584"},{"type":"ADVISORY","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42055.json"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2489866"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-13T04:02:52.959063476Z"}}