When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 encoder instructions can cause NGINX worker processes to terminate or cause or other potential impact.
2024-05-29T16:15:10.043
2025-01-24T16:21:55.993
Analyzed
CVSSv3.1: 6.5 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | f5 | nginx_open_source | < 1.26.1 | Yes |
Application | f5 | nginx_plus | r30 | Yes |
Application | f5 | nginx_plus | r30 | Yes |
Application | f5 | nginx_plus | r30 | Yes |
Application | f5 | nginx_plus | r31 | Yes |
Application | f5 | nginx_plus | r31 | Yes |
Operating System | fedoraproject | fedora | 39 | Yes |
Operating System | fedoraproject | fedora | 40 | Yes |