CVE-2026-40460Medium· 6.5▾ SunlitWhen NGINX Plus or NGINX Open Source are configured to use the HTTP/3 QUIC module, an attacker may be able to spoof their source IP address allowing for bypass of authorization or bypass of rate limiting. Note: Software versions which h…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.4%
0.4% → 0.4%
When NGINX Plus or NGINX Open Source are configured to use the HTTP/3 QUIC module, an attacker may be able to spoof their source IP address allowing for bypass of authorization or bypass of rate limiting. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-55210High· 7.4Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks
CVE-2026-63329Medium· 4.9Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux
CVE-2026-62987Medium· 5.8Fabio is an HTTP(S) and TCP router for deploying applications managed by consul
CVE-2026-85751Critical· 9.8Mailu is a mail server distributed as a set of Docker images
CVE-2026-69183High· 7.5Monkeytype is a minimalistic and customizable typing test
CVE-2026-61682Critical· 9.9kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workloads