CVE-2026-42055High· 8.1▾ MidnightPoC availableNGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass directives are used to proxy HTTP/2 traffic, …
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 44.6 · likelihood 1.3 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Jul 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
2.8%
2.8% → 6.5%
1 GitHub repo
Last analysed / modified upstream
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass directives are used to proxy HTTP/2 traffic, the ignore_invalid_headers directive is set to off, and the large_client_header_buffers directive size is larger than 2 megabytes. A remote, unauthenticated attacker, along with conditions beyond their control, could send large headers while creating an upstream request. This may cause a heap-based buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
dos >= 4.3.0, <= 4.7.0dos = 4.9.0nginx_gateway_fabric >= 1.3.0, <= 1.6.2nginx_gateway_fabric >= 2.0.0, <= 2.6.3nginx_ingress_controller >= 3.5.0, <= 3.7.2nginx_ingress_controller >= 4.0.0, <= 4.0.1nginx_ingress_controller >= 5.0.0, <= 5.5.0nginx_instance_manager >= 2.17.0, <= 2.22.0nginx_open_source >= 1.0.0, <= 1.30.2nginx_open_source >= 1.31.0, <= 1.31.1nginx_plus >= 37.0.0.1, < 37.0.2.1nginx_plus >= r33, < r36nginx_plus = r36waf >= 4.10.0, <= 4.16.0waf >= 5.2.0, <= 5.8.0waf >= 5.9.0, <= 5.13.1discoveryhardened_imagesupdate_infrastructure >= 5.0, < 5.2enterprise_linux = 8.0enterprise_linux = 9.0enterprise_linux = 10.0Upgrade past the affected range:
nginx_plus r36update_infrastructure 5.2Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-42945High· 8.1NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module
CVE-2026-90439Medium· 6.5NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_v3_module module
CVE-2025-25249High· 8.1A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiSwitchManager 7.2.0 through 7.2.6…
CVE-2026-28618High· 8.8In dec_frm_prepare of oapv.c, there is a possible OOB write due to a heap buffer overflow
CVE-2025-15059High· 7.8GIMP PSP File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
CVE-2026-0200High· 8.8In Cellular Modem, there is a possible out-of-bounds write due to a heap buffer overflow