F5 issues out-of-band update for two critical NGINX flaws
F5 has released out-of-band updates for NGINX Plus, NGINX Open Source and NGINX Gateway Fabric. The key fixes are CVE-2026-42530, a use-after-free in HTTP/3 affecting NGINX 1.31.0 to 1.31.1, and CVE-2026-42055, a buffer overflow in the proxy_v2 and gRPC modules affecting NGINX 1.13.10 to 1.31.1. Both are scored 9.2 and can be triggered remotely without authentication to restart NGINX worker processes. F5 notes that code execution may be possible if ASLR is disabled or bypassed.
What this means for your organisation
NGINX usually sits right at the edge, in front of web shops, APIs and customer portals. A flaw triggerable without authentication means anyone on the internet can attempt it. The likely outcome is denial of service and unstable services, but in environments where memory protections are weakened the consequence can extend to code execution on the entry point itself. Note that the gRPC and proxy modules have been vulnerable across many releases, so older installations are in scope too.
Berigo recommends
- Inventory every NGINX instance, including those bundled inside container images and packaged appliances.
- Update to the release F5 specifies, prioritising internet-facing instances.
- Disable HTTP/3 temporarily where you cannot update quickly.
- Verify that ASLR is enabled on the hosts running NGINX.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch