When NGINX Open Source is configured to proxy HTTP/2 traffic by setting proxy_http_version to 2, and also uses proxy_set_body, an attacker may be able to inject frame headers and payload bytes to the upstream peer. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CVSS Details
- CVSS 4.0 Base Score: 6.3 (MEDIUM)
- CVSS 4.0 Vector: (CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
- CVSS 3.1 Base Score: 5.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade nginx-mod-streamUpgrade nginx-mod-http-xslt-filterUpgrade nginx-debuginfoUpgrade nginx-mod-http-perlUpgrade nginx-mod-develUpgrade nginx-filesystemUpgrade nginx-mod-http-image-filterUpgrade nginxUpgrade nginx-mod-http-geoipUpgrade nginx-mod-mailUpgrade nginx-coreUpgrade nginx-all-modules | Jun 8, 2026 | Jun 8, 2026 |
| Amazon_linux_2023 | — | Upgrade nginx-debugsourceUpgrade nginx-mod-http-xslt-filterUpgrade nginx-mod-http-perlUpgrade nginx-mod-http-image-filterUpgrade nginx-coreUpgrade nginx-debuginfoUpgrade nginx-mod-mail-debuginfoUpgrade nginx-mod-streamUpgrade nginx-mod-http-perl-debuginfoUpgrade nginx-mod-http-image-filter-debuginfoUpgrade nginx-all-modulesUpgrade nginx-mod-http-xslt-filter-debuginfoUpgrade nginx-mod-mailUpgrade nginx-mod-stream-debuginfoUpgrade nginx-filesystemUpgrade nginx-core-debuginfoUpgrade nginx-mod-develUpgrade nginx | May 28, 2026 | May 13, 2026 |
| Freebsd | — | Upgrade nginx-develUpgrade nginx | May 21, 2026 | May 19, 2026 |
| Nginx | — | Upgrade to nginx version 1.31.0Upgrade to nginx version 1.30.1 | May 14, 2026 | May 13, 2026 |
| Redhat_linux | — | No solution exists | Aug 24, 2026 | May 13, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub