When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 requests can cause NGINX worker processes to terminate or causeĀ other potential impact. This attack requires that a request be specifically timed during the connection draining process, which the attacker has no visibility and limited influence over.
2024-05-29T16:15:09.800
2025-01-24T16:01:04.653
Analyzed
CVSSv3.1: 4.8 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | f5 | nginx_open_source | < 1.26.1 | Yes |
Application | f5 | nginx_plus | r30 | Yes |
Application | f5 | nginx_plus | r30 | Yes |
Application | f5 | nginx_plus | r30 | Yes |
Application | f5 | nginx_plus | r31 | Yes |
Application | f5 | nginx_plus | r31 | Yes |
Operating System | fedoraproject | fedora | 39 | Yes |
Operating System | fedoraproject | fedora | 40 | Yes |