NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass directives are used to proxy HTTP/2 traffic, the ignore_invalid_headers directive is set to off, and the large_client_header_buffers directive size is larger than 2 megabytes. A remote, unauthenticated attacker, along with conditions beyond their control, could send large headers while creating an upstream request. This may cause a heap-based buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
References
| Link | Resource |
|---|---|
| https://my.f5.com/manage/s/article/K000161584 | Vendor Advisory |
| https://access.redhat.com/errata/RHSA-2026:27197 | Third Party Advisory |
| https://access.redhat.com/errata/RHSA-2026:36331 | Third Party Advisory |
| https://access.redhat.com/errata/RHSA-2026:36364 | Third Party Advisory |
| https://access.redhat.com/errata/RHSA-2026:36618 | Third Party Advisory |
| https://access.redhat.com/errata/RHSA-2026:36639 | Third Party Advisory |
| https://access.redhat.com/errata/RHSA-2026:38847 | Third Party Advisory |
| https://access.redhat.com/errata/RHSA-2026:44481 | Third Party Advisory |
| https://access.redhat.com/errata/RHSA-2026:46836 | Third Party Advisory |
| https://access.redhat.com/errata/RHSA-2026:58981 | |
| https://access.redhat.com/security/cve/CVE-2026-42055 | Third Party Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2489866 | Issue Tracking Third Party Advisory |
| https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42055.json | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
No history.
Information
Published : 2026-06-17 15:16
Updated : 2026-09-14 13:18
NVD link : CVE-2026-42055
Mitre link : CVE-2026-42055
CVE.ORG link : CVE-2026-42055
JSON object : View
Products Affected
redhat
- enterprise_linux
- discovery
- hardened_images
- update_infrastructure
f5
- nginx_open_source
- nginx_ingress_controller
- nginx_plus
- waf
- nginx_instance_manager
- dos
- nginx_gateway_fabric
