When NGINX Plus or NGINX Open Source are configured to use the HTTP/3 QUIC module, an attacker may be able to spoof their source IP address allowing for bypass of authorization or bypass of rate limiting. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CVSS Details
- CVSS 4.0 Base Score: 6.9 (MEDIUM)
- CVSS 4.0 Vector: (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade nginx | May 15, 2026 | May 13, 2026 |
| Amazon Linux Ami 2 | — | Upgrade nginxUpgrade nginx-coreUpgrade nginx-filesystemUpgrade nginx-mod-http-image-filterUpgrade nginx-mod-http-perlUpgrade nginx-all-modulesUpgrade nginx-mod-mailUpgrade nginx-mod-streamUpgrade nginx-mod-http-geoipUpgrade nginx-mod-develUpgrade nginx-debuginfoUpgrade nginx-mod-http-xslt-filter | Jun 8, 2026 | Jun 8, 2026 |
| Amazon_linux_2023 | — | Upgrade nginxUpgrade nginx-mod-http-xslt-filter-debuginfoUpgrade nginx-mod-http-perlUpgrade nginx-core-debuginfoUpgrade nginx-coreUpgrade nginx-mod-http-image-filterUpgrade nginx-debugsourceUpgrade nginx-mod-http-perl-debuginfoUpgrade nginx-mod-develUpgrade nginx-mod-http-xslt-filterUpgrade nginx-mod-mail-debuginfoUpgrade nginx-mod-mailUpgrade nginx-mod-stream-debuginfoUpgrade nginx-mod-http-image-filter-debuginfoUpgrade nginx-debuginfoUpgrade nginx-filesystemUpgrade nginx-all-modulesUpgrade nginx-mod-stream | May 28, 2026 | May 13, 2026 |
| Debian | — | Upgrade nginx | Jul 23, 2026 | Jul 23, 2026 |
| Freebsd | — | Upgrade nginxUpgrade nginx-devel | May 21, 2026 | May 19, 2026 |
| Nginx | — | Upgrade to nginx version 1.31.0Upgrade to nginx version 1.30.1 | May 14, 2026 | May 13, 2026 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | May 13, 2026 |
| Ubuntu | — | Upgrade nginx-lightUpgrade nginx-coreUpgrade nginxUpgrade nginx-fullUpgrade nginx-extras | Jun 2, 2026 | Jun 1, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jun 18, 2026 | May 13, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub