cve-2026-42055

CRITICAL CVSS 9.2 nvd
Description

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass directives are used to proxy HTTP/2 traffic, the ignore_invalid_headers directive is set to off, and the large_client_header_buffers directive size is larger than 2 megabytes. A remote, unauthenticated attacker, along with conditions beyond their control, could send large headers while creating an upstream request. This may cause a heap-based buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Timeline
Published
2026-06-17
Last Modified
2026-09-14
CVSS Details
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
Affected Products
  • f5 dos
  • f5 nginx_gateway_fabric
  • f5 nginx_ingress_controller
  • f5 nginx_instance_manager
  • f5 nginx_open_source
  • f5 nginx_plus
  • f5 waf
  • redhat discovery
  • redhat hardened_images
  • redhat update_infrastructure
  • redhat enterprise_linux
Weaknesses (CWE)
CVSS metrics
Version Base Severity Vector Exploitability Impact Source
4.0 9.2 CRITICAL CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X f5sirt@f5.com
3.1 8.1 HIGH CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H 2.2 5.9 f5sirt@f5.com
3.1 8.1 HIGH CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H 2.2 5.9 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
CPE configurations
OR
CPE Version range Vulnerable
cpe:2.3:a:f5:dos:*:*:*:*:*:nginx:*:* >= 4.3.0, <= 4.7.0 yes
cpe:2.3:a:f5:dos:4.9.0:*:*:*:*:nginx:*:* — yes
cpe:2.3:a:f5:nginx_gateway_fabric:*:*:*:*:*:*:*:* >= 1.3.0, <= 1.6.2 yes
cpe:2.3:a:f5:nginx_gateway_fabric:*:*:*:*:*:*:*:* >= 2.0.0, <= 2.6.3 yes
cpe:2.3:a:f5:nginx_ingress_controller:*:*:*:*:continuous_releases:*:*:* >= 3.5.0, <= 3.7.2 yes
cpe:2.3:a:f5:nginx_ingress_controller:*:*:*:*:continuous_releases:*:*:* >= 4.0.0, <= 4.0.1 yes
cpe:2.3:a:f5:nginx_ingress_controller:*:*:*:*:continuous_releases:*:*:* >= 5.0.0, <= 5.5.0 yes
cpe:2.3:a:f5:nginx_instance_manager:*:*:*:*:*:*:*:* >= 2.17.0, <= 2.22.0 yes
cpe:2.3:a:f5:nginx_open_source:*:*:*:*:*:*:*:* >= 1.0.0, <= 1.30.2 yes
cpe:2.3:a:f5:nginx_open_source:*:*:*:*:*:*:*:* >= 1.31.0, <= 1.31.1 yes
cpe:2.3:a:f5:nginx_plus:*:*:*:*:long-term_support:*:*:* >= 37.0.0.1, < 37.0.2.1 yes
cpe:2.3:a:f5:nginx_plus:*:*:*:*:continuous_releases:*:*:* >= r33, < r36 yes
cpe:2.3:a:f5:nginx_plus:r36:-:*:*:continuous_releases:*:*:* — yes
cpe:2.3:a:f5:nginx_plus:r36:p1:*:*:continuous_releases:*:*:* — yes
cpe:2.3:a:f5:nginx_plus:r36:p2:*:*:continuous_releases:*:*:* — yes
cpe:2.3:a:f5:nginx_plus:r36:p3:*:*:continuous_releases:*:*:* — yes
cpe:2.3:a:f5:nginx_plus:r36:p4:*:*:continuous_releases:*:*:* — yes
cpe:2.3:a:f5:nginx_plus:r36:p5:*:*:continuous_releases:*:*:* — yes
cpe:2.3:a:f5:waf:*:*:*:*:*:nginx:*:* >= 4.10.0, <= 4.16.0 yes
cpe:2.3:a:f5:waf:*:*:*:*:*:nginx:*:* >= 5.2.0, <= 5.8.0 yes
cpe:2.3:a:f5:waf:*:*:*:*:*:nginx:*:* >= 5.9.0, <= 5.13.1 yes
OR
CPE Version range Vulnerable
cpe:2.3:a:redhat:discovery:-:*:*:*:*:*:*:* — yes
cpe:2.3:a:redhat:hardened_images:-:*:*:*:*:*:*:* — yes
cpe:2.3:a:redhat:update_infrastructure:*:*:*:*:*:*:*:* >= 5.0, < 5.2 yes
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:* — yes
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:* — yes
cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:* — yes
NVD metadata
NVD status
Modified
Source identifier
f5sirt@f5.com
References
Linked Vulnerabilities

{
  "cvss": 9.2,
  "datePublished": "2026-06-17T15:16:50.353",
  "dateUpdated": "2026-09-14T13:18:34.690",
  "description": "NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass directives are used to proxy HTTP/2 traffic, the ignore_invalid_headers directive is set to off, and the large_client_header_buffers directive size is larger than 2 megabytes. A remote, unauthenticated attacker, along with conditions beyond their control, could send large headers while creating an upstream request. This may cause a heap-based buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. \n\n\nNote: Software versions which have reached End of Technical Support (EoTS) are not evaluated.",
  "id": "CVE-2026-42055",
  "raw": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unknown",
            "modules": [
              "ngx_http_proxy_v2_module",
              "ngx_http_grpc_module"
            ],
            "product": "NGINX Open Source",
            "vendor": "F5",
            "versions": [
              {
                "lessThan": "1.31.2",
                "status": "affected",
                "version": "1.13.10",
                "versionType": "custom"
              },
              {
                "lessThan": "1.30.3",
                "status": "affected",
                "version": "1.30.2",
                "versionType": "custom"
              }
            ]
          },
          {
            "defaultStatus": "unaffected",
            "modules": [
              "ngx_http_proxy_v2_module",
              "ngx_http_grpc_module"
            ],
            "product": "NGINX Plus",
            "vendor": "F5",
            "versions": [
              {
                "lessThan": "37.0.2.1",
                "status": "affected",
                "version": "37.0",
                "versionType": "custom"
              },
              {
                "lessThan": "R36 P6",
                "status": "affected",
                "version": "R36",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "f5sirt@f5.com"
      },
      {
        "affectedData": [
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/o:redhat:enterprise_linux:10.2"
            ],
            "defaultStatus": "affected",
            "packageName": "nginx",
            "product": "Red Hat Enterprise Linux 10",
            "vendor": "Red Hat",
            "versions": [
              {
                "lessThan": "*",
                "status": "unaffected",
                "version": "2:1.26.3-6.el10_2.5",
                "versionType": "rpm"
              }
            ]
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:enterprise_linux:8"
            ],
            "defaultStatus": "affected",
            "packageName": "nginx:1.24",
            "product": "Red Hat Enterprise Linux 8",
            "vendor": "Red Hat",
            "versions": [
              {
                "lessThan": "*",
                "status": "unaffected",
                "version": "8100020260707171317.489197e6",
                "versionType": "rpm"
              }
            ]
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:enterprise_linux:9"
            ],
            "defaultStatus": "affected",
            "packageName": "nginx",
            "product": "Red Hat Enterprise Linux 9",
            "vendor": "Red Hat",
            "versions": [
              {
                "lessThan": "*",
                "status": "unaffected",
                "version": "2:1.20.1-28.el9_8.4",
                "versionType": "rpm"
              }
            ]
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:enterprise_linux:9"
            ],
            "defaultStatus": "affected",
            "packageName": "nginx:1.24",
            "product": "Red Hat Enterprise Linux 9",
            "vendor": "Red Hat",
            "versions": [
              {
                "lessThan": "*",
                "status": "unaffected",
                "version": "9080020260707164406.9",
                "versionType": "rpm"
              }
            ]
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:enterprise_linux:9"
            ],
            "defaultStatus": "affected",
            "packageName": "nginx:1.26",
            "product": "Red Hat Enterprise Linux 9",
            "vendor": "Red Hat",
            "versions": [
              {
                "lessThan": "*",
                "status": "unaffected",
                "version": "9080020260707110000.9",
                "versionType": "rpm"
              }
            ]
          },
          {
            "collectionURL": "https://catalog.redhat.com/software/containers/",
            "cpes": [
              "cpe:/a:redhat:discovery:2::el9"
            ],
            "defaultStatus": "affected",
            "packageName": "discovery/discovery-ui-rhel9",
            "product": "Red Hat Discovery 2",
            "vendor": "Red Hat",
            "versions": [
              {
                "lessThan": "*",
                "status": "unaffected",
                "version": "1784821750",
                "versionType": "rpm"
              }
            ]
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:hummingbird:1"
            ],
            "defaultStatus": "affected",
            "packageName": "nginx-main",
            "product": "Red Hat Hardened Images",
            "vendor": "Red Hat",
            "versions": [
              {
                "lessThan": "*",
                "status": "unaffected",
                "version": "1.30.3-2.hum1",
                "versionType": "rpm"
              }
            ]
          },
          {
            "collectionURL": "https://catalog.redhat.com/software/containers/",
            "cpes": [
              "cpe:/a:redhat:rhui:5::el9"
            ],
            "defaultStatus": "affected",
            "packageName": "rhui5/cds-kubernetes-rhel9",
            "product": "Red Hat Update Infrastructure 5",
            "vendor": "Red Hat",
            "versions": [
              {
                "lessThan": "*",
                "status": "unaffected",
                "version": "1784794818",
                "versionType": "rpm"
              }
            ]
          },
          {
            "collectionURL": "https://catalog.redhat.com/software/containers/",
            "cpes": [
              "cpe:/a:redhat:rhui:5::el9"
            ],
            "defaultStatus": "affected",
            "packageName": "rhui5/cds-rhel9",
            "product": "Red Hat Update Infrastructure 5",
            "vendor": "Red Hat",
            "versions": [
              {
                "lessThan": "*",
                "status": "unaffected",
                "version": "1784794778",
                "versionType": "rpm"
              }
            ]
          },
          {
            "collectionURL": "https://catalog.redhat.com/software/containers/",
            "cpes": [
              "cpe:/a:redhat:rhui:5::el9"
            ],
            "defaultStatus": "affected",
            "packageName": "rhui5/rhua-rhel9",
            "product": "Red Hat Update Infrastructure 5",
            "vendor": "Red Hat",
            "versions": [
              {
                "lessThan": "*",
                "status": "unaffected",
                "version": "1784795076",
                "versionType": "rpm"
              }
            ]
          },
          {
            "collectionURL": "https://catalog.redhat.com/software/containers/",
            "cpes": [
              "cpe:/a:redhat:rhui:5::el9"
            ],
            "defaultStatus": "affected",
            "packageName": "rhui5/cds-kubernetes-tp-rhel9",
            "product": "Red Hat Update Infrastructure 5",
            "vendor": "Red Hat",
            "versions": [
              {
                "lessThan": "*",
                "status": "unaffected",
                "version": "1787241211",
                "versionType": "rpm"
              }
            ]
          },
          {
            "collectionURL": "https://catalog.redhat.com/software/containers/",
            "cpes": [
              "cpe:/a:redhat:rhui:5::el9"
            ],
            "defaultStatus": "affected",
            "packageName": "rhui5/rhua-tp-rhel9",
            "product": "Red Hat Update Infrastructure 5",
            "vendor": "Red Hat",
            "versions": [
              {
                "lessThan": "*",
                "status": "unaffected",
                "version": "1787241260",
                "versionType": "rpm"
              }
            ]
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:openshift_data_foundation:4"
            ],
            "defaultStatus": "unaffected",
            "packageName": "odf4/ocs-client-console-rhel9",
            "product": "Red Hat Openshift Data Foundation 4",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:openshift_data_foundation:4"
            ],
            "defaultStatus": "affected",
            "packageName": "odf4/odf-console-rhel9",
            "product": "Red Hat Openshift Data Foundation 4",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:openshift_data_foundation:4"
            ],
            "defaultStatus": "unaffected",
            "packageName": "odf4/odf-multicluster-console-rhel9",
            "product": "Red Hat Openshift Data Foundation 4",
            "vendor": "Red Hat"
          }
        ],
        "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:f5:dos:*:*:*:*:*:nginx:*:*",
                "matchCriteriaId": "0772572C-26F9-4FA4-B9E6-BA40ED59F569",
                "versionEndIncluding": "4.7.0",
                "versionStartIncluding": "4.3.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:f5:dos:4.9.0:*:*:*:*:nginx:*:*",
                "matchCriteriaId": "DACAC9CB-16D3-4F55-A466-70035779B387",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:f5:nginx_gateway_fabric:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "15B7F1FD-0C49-460F-9CB8-23DA730EC4BE",
                "versionEndIncluding": "1.6.2",
                "versionStartIncluding": "1.3.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:f5:nginx_gateway_fabric:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "67499218-62EE-4217-897D-AF3E92D92E39",
                "versionEndIncluding": "2.6.3",
                "versionStartIncluding": "2.0.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:f5:nginx_ingress_controller:*:*:*:*:continuous_releases:*:*:*",
                "matchCriteriaId": "E54B5C35-49D7-43F6-B57C-4606F75192CE",
                "versionEndIncluding": "3.7.2",
                "versionStartIncluding": "3.5.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:f5:nginx_ingress_controller:*:*:*:*:continuous_releases:*:*:*",
                "matchCriteriaId": "DB6D172C-2716-40B9-B74C-D3029EDD171F",
                "versionEndIncluding": "4.0.1",
                "versionStartIncluding": "4.0.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:f5:nginx_ingress_controller:*:*:*:*:continuous_releases:*:*:*",
                "matchCriteriaId": "B4ED6BD2-BFBB-498C-9E43-508997695429",
                "versionEndIncluding": "5.5.0",
                "versionStartIncluding": "5.0.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:f5:nginx_instance_manager:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "BCFCE3FC-61E0-4749-8F09-EEB4B09B1218",
                "versionEndIncluding": "2.22.0",
                "versionStartIncluding": "2.17.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:f5:nginx_open_source:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "AD753AAB-7ADA-4B0D-A33B-74E149277C4D",
                "versionEndIncluding": "1.30.2",
                "versionStartIncluding": "1.0.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:f5:nginx_open_source:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "4B3A862B-427A-440A-93AB-FFA1FB2E3909",
                "versionEndIncluding": "1.31.1",
                "versionStartIncluding": "1.31.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:f5:nginx_plus:*:*:*:*:long-term_support:*:*:*",
                "matchCriteriaId": "7B91F29E-E9A7-4EB3-8858-2786A85E3005",
                "versionEndExcluding": "37.0.2.1",
                "versionStartIncluding": "37.0.0.1",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:f5:nginx_plus:*:*:*:*:continuous_releases:*:*:*",
                "matchCriteriaId": "277F91F7-F75B-463E-A342-4624E52ED3ED",
                "versionEndExcluding": "r36",
                "versionStartIncluding": "r33",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:f5:nginx_plus:r36:-:*:*:continuous_releases:*:*:*",
                "matchCriteriaId": "6FCF8770-25AF-4A07-916B-16F50357A44E",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:f5:nginx_plus:r36:p1:*:*:continuous_releases:*:*:*",
                "matchCriteriaId": "D5C601A4-8DA6-443E-8284-6DCD34E4F3CB",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:f5:nginx_plus:r36:p2:*:*:continuous_releases:*:*:*",
                "matchCriteriaId": "EB6684A4-3869-4C21-B87A-129C30C99C28",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:f5:nginx_plus:r36:p3:*:*:continuous_releases:*:*:*",
                "matchCriteriaId": "B2AC5070-A6B7-440B-A45A-90E751FF103E",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:f5:nginx_plus:r36:p4:*:*:continuous_releases:*:*:*",
                "matchCriteriaId": "D7907F59-BBCC-4B5B-8BBC-92C14BB804D2",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:f5:nginx_plus:r36:p5:*:*:continuous_releases:*:*:*",
                "matchCriteriaId": "987F269A-A0F6-48D4-9C30-7F92A2267D45",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:f5:waf:*:*:*:*:*:nginx:*:*",
                "matchCriteriaId": "EB1118B4-3EA7-4A69-8259-86BB8837FC00",
                "versionEndIncluding": "4.16.0",
                "versionStartIncluding": "4.10.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:f5:waf:*:*:*:*:*:nginx:*:*",
                "matchCriteriaId": "2DB79E6C-08B0-4341-BCBE-B8070DDAA7AF",
                "versionEndIncluding": "5.8.0",
                "versionStartIncluding": "5.2.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:f5:waf:*:*:*:*:*:nginx:*:*",
                "matchCriteriaId": "03FC0AE0-1D26-4002-92DD-1895A38F6382",
                "versionEndIncluding": "5.13.1",
                "versionStartIncluding": "5.9.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      },
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:redhat:discovery:-:*:*:*:*:*:*:*",
                "matchCriteriaId": "B5B1D946-5978-4818-BF21-A43D9C1365E1",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:redhat:hardened_images:-:*:*:*:*:*:*:*",
                "matchCriteriaId": "87DEB507-5B64-47D7-9A50-3B87FD1E571F",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:redhat:update_infrastructure:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "3FAF1DEF-A926-43D4-B94E-E7E02C813CD9",
                "versionEndExcluding": "5.2",
                "versionStartIncluding": "5.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*",
                "matchCriteriaId": "F4CFF558-3C47-480D-A2F0-BABF26042943",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*",
                "matchCriteriaId": "7F6FB57C-2BC7-487C-96DD-132683AEB35D",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*",
                "matchCriteriaId": "D65C2163-CFC2-4ABB-8F4E-CB09CEBD006C",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass directives are used to proxy HTTP/2 traffic, the ignore_invalid_headers directive is set to off, and the large_client_header_buffers directive size is larger than 2 megabytes. A remote, unauthenticated attacker, along with conditions beyond their control, could send large headers while creating an upstream request. This may cause a heap-based buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. \n\n\nNote: Software versions which have reached End of Technical Support (EoTS) are not evaluated."
      }
    ],
    "id": "CVE-2026-42055",
    "lastModified": "2026-09-14T13:18:34.690",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 2.2,
          "impactScore": 5.9,
          "source": "f5sirt@f5.com",
          "type": "Secondary"
        },
        {
          "cvssData": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 2.2,
          "impactScore": 5.9,
          "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
          "type": "Secondary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "HIGH",
            "attackRequirements": "PRESENT",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 9.2,
            "baseSeverity": "CRITICAL",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "NONE",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "HIGH",
            "vulnConfidentialityImpact": "HIGH",
            "vulnIntegrityImpact": "HIGH",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "f5sirt@f5.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-42055",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-06-17T00:00:00+00:00",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-06-17T15:16:50.353",
    "references": [
      {
        "source": "f5sirt@f5.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://my.f5.com/manage/s/article/K000161584"
      },
      {
        "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
        "tags": [
          "Third Party Advisory"
        ],
        "url": "https://access.redhat.com/errata/RHSA-2026:27197"
      },
      {
        "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
        "tags": [
          "Third Party Advisory"
        ],
        "url": "https://access.redhat.com/errata/RHSA-2026:36331"
      },
      {
        "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
        "tags": [
          "Third Party Advisory"
        ],
        "url": "https://access.redhat.com/errata/RHSA-2026:36364"
      },
      {
        "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
        "tags": [
          "Third Party Advisory"
        ],
        "url": "https://access.redhat.com/errata/RHSA-2026:36618"
      },
      {
        "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
        "tags": [
          "Third Party Advisory"
        ],
        "url": "https://access.redhat.com/errata/RHSA-2026:36639"
      },
      {
        "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
        "tags": [
          "Third Party Advisory"
        ],
        "url": "https://access.redhat.com/errata/RHSA-2026:38847"
      },
      {
        "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
        "tags": [
          "Third Party Advisory"
        ],
        "url": "https://access.redhat.com/errata/RHSA-2026:44481"
      },
      {
        "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
        "tags": [
          "Third Party Advisory"
        ],
        "url": "https://access.redhat.com/errata/RHSA-2026:46836"
      },
      {
        "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
        "url": "https://access.redhat.com/errata/RHSA-2026:58981"
      },
      {
        "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
        "tags": [
          "Third Party Advisory"
        ],
        "url": "https://access.redhat.com/security/cve/CVE-2026-42055"
      },
      {
        "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
        "tags": [
          "Issue Tracking",
          "Third Party Advisory"
        ],
        "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2489866"
      },
      {
        "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
        "tags": [
          "Third Party Advisory"
        ],
        "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42055.json"
      }
    ],
    "sourceIdentifier": "f5sirt@f5.com",
    "vulnStatus": "Modified",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-122"
          }
        ],
        "source": "f5sirt@f5.com",
        "type": "Secondary"
      },
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-787"
          }
        ],
        "source": "nvd@nist.gov",
        "type": "Primary"
      },
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-131"
          }
        ],
        "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
        "type": "Secondary"
      }
    ]
  },
  "severity": "CRITICAL",
  "source": "nvd",
  "title": "NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules"
}
View JSON API Download JSON