Colleagues, please note: critical vulnerabilities in NGINX Open Source (RCE)

From cybersecurity: F5 has released patches for two critical NGINX vulnerabilities (CVE-2026-42530, CVE-2026-42055) that can enable remote code execution under certain configurations.
Brief:
- CVE-2026-42530: use-after-free in HTTP/3 (QPACK) — attacker can achieve RCE when HTTP/3 is enabled.
- CVE-2026-42055: heap overflow in proxy/grpc when proxying HTTP/2 with large_client_header_buffers configured and ignore_invalid_headers set.
Actions:
- Upgrade NGINX/F5 to patched versions.
- Temporarily disable HTTP/3 and/or remove ignore_invalid_headers off / reduce large_client_header_buffers.
Why it matters: both have CVSS 9.2 — high risk for public-facing services.
Do you have plans for an emergency update?
#cybersecurity #NGINX #F5 #RCE

