F5 NGINX OSS
cpe:2.3:a:f5:nginx_open_source:*:*:*:*:*:*:*
- >= 1.25.0, <= 1.25.3
A denial-of-service vulnerability has been identified in NGINX Plus and NGINX Open Source versions 1.25.0 prior to 1.25.4, and 1.26.0, when the experimental HTTP/3 QUIC module is enabled. Undisclosed requests can cause NGINX worker processes to crash, disrupting traffic until the process restarts.
Exploitation of this vulnerability leads to a crash of the NGINX worker process, causing a temporary disruption in service until the process is restarted.
Users can upgrade to NGINX versions 1.25.4 or 1.27.0. If using NGINX Plus, refer to the NGINX Plus release notes for the appropriate version. For NGINX Open Source, version 1.25.4 includes the fix. Alternatively, the HTTP/3 module can be disabled in the NGINX configuration.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.