{"id":"CVE-2026-42530","aliases":["BIT-nginx-2026-42530","BIT-nginx-gateway-2026-42530"],"url":"https://o3.security/vulnerability/CVE-2026-42530","summary":null,"details":"NGINX Open Source has a vulnerability in the ngx_http_v3_module module. When NGINX Open Source is configured to use the HTTP/3 QUIC module, a remote unauthenticated attacker along with conditions beyond their control can use a specially crafted HTTP/3 session to reopen a QPACK encoder stream. This may cause a Use-after-Free in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR.  \n\n\nNote: Software versions which have reached End of Technical Support (EoTS) are not evaluated.","published":"2026-06-17T15:16:50.630Z","modified":"2026-08-17T16:27:03.133727357Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[],"fix":null,"references":[{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:20351"},{"type":"ADVISORY","url":"https://access.redhat.com/security/cve/CVE-2026-42530"},{"type":"ADVISORY","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2489872"},{"type":"ADVISORY","url":"https://my.f5.com/manage/s/article/K000161616"},{"type":"ADVISORY","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42530.json"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-17T16:27:03.133727357Z"}}