{
  "threat_severity" : "Important",
  "public_date" : "2026-06-17T14:04:32Z",
  "bugzilla" : {
    "description" : "nginx: NGINX: Arbitrary code execution or Denial of Service via heap-based buffer overflow with crafted HTTP/2 headers",
    "id" : "2489866",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2489866"
  },
  "cvss3" : {
    "cvss3_base_score" : "8.1",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
    "status" : "verified"
  },
  "cwe" : "CWE-131",
  "details" : [ "NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass directives are used to proxy HTTP/2 traffic, the ignore_invalid_headers directive is set to off, and the large_client_header_buffers directive size is larger than 2 megabytes. A remote, unauthenticated attacker, along with conditions beyond their control, could send large headers while creating an upstream request. This may cause a heap-based buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. \nNote: Software versions which have reached End of Technical Support (EoTS) are not evaluated.", "A flaw was found in NGINX. When NGINX is configured to proxy HTTP/2 traffic using the ngx_http_proxy_v2_module or ngx_http_grpc_module with specific settings, a remote, unauthenticated attacker can send specially crafted large headers. This can trigger a heap-based buffer overflow, leading to a restart of the NGINX worker process and a Denial of Service (DoS). Under certain conditions, such as when Address Space Layout Randomization (ASLR) is disabled or bypassed, this vulnerability could also allow for arbitrary code execution." ],
  "statement" : "This issue is classified as Important severity primarily because:\nConditions for Exploitation: A remote, unauthenticated attacker can only exploit this if NGINX is explicitly configured to proxy HTTP/2 traffic using the ngx_http_proxy_v2_module or ngx_http_grpc_module.\nImpact Limitations: While the flaw reliably causes a Denial of Service (worker restart), achieving arbitrary code execution is highly complex in modern environments as it requires the attacker to bypass or disable Address Space Layout Randomization (ASLR)",
  "affected_release" : [ {
    "product_name" : "Red Hat Enterprise Linux 10",
    "release_date" : "2026-07-07T00:00:00Z",
    "advisory" : "RHSA-2026:36364",
    "cpe" : "cpe:/o:redhat:enterprise_linux:10.2",
    "package" : "nginx-2:1.26.3-6.el10_2.5"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "release_date" : "2026-07-13T00:00:00Z",
    "advisory" : "RHSA-2026:38847",
    "cpe" : "cpe:/a:redhat:enterprise_linux:8",
    "package" : "nginx:1.24-8100020260707171317.489197e6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "release_date" : "2026-07-07T00:00:00Z",
    "advisory" : "RHSA-2026:36331",
    "cpe" : "cpe:/a:redhat:enterprise_linux:9",
    "package" : "nginx-2:1.20.1-28.el9_8.4"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "release_date" : "2026-07-08T00:00:00Z",
    "advisory" : "RHSA-2026:36618",
    "cpe" : "cpe:/a:redhat:enterprise_linux:9",
    "package" : "nginx:1.24-9080020260707164406.9"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "release_date" : "2026-07-08T00:00:00Z",
    "advisory" : "RHSA-2026:36639",
    "cpe" : "cpe:/a:redhat:enterprise_linux:9",
    "package" : "nginx:1.26-9080020260707110000.9"
  }, {
    "product_name" : "Red Hat Discovery 2",
    "release_date" : "2026-07-27T00:00:00Z",
    "advisory" : "RHSA-2026:46836",
    "cpe" : "cpe:/a:redhat:discovery:2::el9",
    "package" : "discovery/discovery-ui-rhel9:1784821750"
  }, {
    "product_name" : "Red Hat Hardened Images",
    "release_date" : "2026-06-19T00:00:00Z",
    "advisory" : "RHSA-2026:27197",
    "cpe" : "cpe:/a:redhat:hummingbird:1",
    "package" : "nginx-main-1.30.3-2.hum1"
  }, {
    "product_name" : "Red Hat Update Infrastructure 5",
    "release_date" : "2026-07-23T00:00:00Z",
    "advisory" : "RHSA-2026:44481",
    "cpe" : "cpe:/a:redhat:rhui:5::el9",
    "package" : "rhui5/cds-kubernetes-rhel9:1784794818"
  }, {
    "product_name" : "Red Hat Update Infrastructure 5",
    "release_date" : "2026-07-23T00:00:00Z",
    "advisory" : "RHSA-2026:44481",
    "cpe" : "cpe:/a:redhat:rhui:5::el9",
    "package" : "rhui5/cds-rhel9:1784794778"
  }, {
    "product_name" : "Red Hat Update Infrastructure 5",
    "release_date" : "2026-07-23T00:00:00Z",
    "advisory" : "RHSA-2026:44481",
    "cpe" : "cpe:/a:redhat:rhui:5::el9",
    "package" : "rhui5/rhua-rhel9:1784795076"
  }, {
    "product_name" : "Red Hat Update Infrastructure 5",
    "release_date" : "2026-08-24T00:00:00Z",
    "advisory" : "RHSA-2026:58981",
    "cpe" : "cpe:/a:redhat:rhui:5::el9",
    "package" : "rhui5/cds-kubernetes-tp-rhel9:1787241211"
  }, {
    "product_name" : "Red Hat Update Infrastructure 5",
    "release_date" : "2026-08-24T00:00:00Z",
    "advisory" : "RHSA-2026:58981",
    "cpe" : "cpe:/a:redhat:rhui:5::el9",
    "package" : "rhui5/rhua-tp-rhel9:1787241260"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat Openshift Data Foundation 4",
    "fix_state" : "Not affected",
    "package_name" : "odf4/ocs-client-console-rhel9",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4",
    "fix_state" : "Affected",
    "package_name" : "odf4/odf-console-rhel9",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4",
    "fix_state" : "Not affected",
    "package_name" : "odf4/odf-multicluster-console-rhel9",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2026-42055\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-42055\nhttps://my.f5.com/manage/s/article/K000161584" ],
  "name" : "CVE-2026-42055",
  "mitigation" : {
    "value" : "To mitigate this vulnerability, ensure that the `ignore_invalid_headers` directive is set to `on` in your NGINX configuration, or reduce the size specified by the `large_client_header_buffers` directive to 2 megabytes or less. These changes require an NGINX service reload or restart to take effect. Reloading the NGINX service is generally safe, but a restart will briefly interrupt service.",
    "lang" : "en:us"
  },
  "csaw" : false
}