FixVibe
覆盖FixVibehigh

有条件 NGINX HTTP/2 和 gRPC 代理缓冲区溢出 (CVE-2026-42055) ZXCVFIXVIBESEND ZXCVFIXVIBESEG1 CVE-2026-42055 影响特定 NGINX HTTP/2 和 gRPC 代理配置。查看所需条件、已修复版本、影响和 ZXCVFIXVIBETOKEN1ZXCV 覆盖范围。 ZXCVFIXVIBESEND ZXCVFIXVIBESEG2 CVE-2026-42055 是 NGINX HTTP/2 和 gRPC 上游代理中基于条件堆的缓冲区溢出。 F5 在 CVSS v3.1 下的得分为 8.1 高,而 nginx.org 将其分类为中。利用该漏洞需要几个不常见的配置先决条件,包括超大的客户端标头缓冲区;工作进程重启是直接记录的影响,并且代码执行还需要禁用或绕过 ASLR。 ZXCVFIXVIBETOKEN1ZXCV 报告受影响的官方 NGINX 开源容器部署的保守存储库证据,并且不执行危险的主动证明。 ZXCVFIXVIBESEND ZXCVFIXVIBESEG3 ZXCVFIXVIBETOKEN2ZXCV 是用于上游 HTTP/2 和 gRPC 代理的 NGINX 模块中基于堆的缓冲区溢出。这是有条件的,而不是每个 NGINX 部署中的全面漏洞:受影响的代理行为、禁用的无效标头过滤和超大的非默认客户端标头缓冲区都必须存在 CVE-2026-42055ZXCVFIXVIBETOKEN1ZXCV。 ZXCVFIXVIBESEND ZXCVFIXVIBESEG4 ## 受影响的配置和版本 ZXCVFIXVIBESEND ZXCVFIXVIBESEG5 仅当所有记录的配置先决条件符合 CVE-2026-42055ZXCVFIXVIBETOKEN1ZXCV 时,供应商记录才涵盖 NGINX Open Source 和 NGINX Plus。对于 NGINX Open Source,受影响的已发布版本为 1.13.10 至 1.30.2,以及 1.31.0 和 1.31.1; nginx.org 将 1.30.3+ 稳定版和 1.31.2+ 主线识别为不易受攻击的 ZXCVFIXVIBETOKEN2ZXCVZXCVFIXVIBETOKEN3ZXCV。 F5 的 CNA 记录还列出了 37.0.2.1 之前的 NGINX Plus R37 37.0 版本以及 R36 P6 之前的 R36 版本受到影响;技术支持结束后的版本未进行评估 ZXCVFIXVIBETOKEN4ZXCVZXCVFIXVIBETOKEN5ZXCV。 ZXCVFIXVIBESEND ZXCVFIXVIBESEG6 ## 影响和严重性 ZXCVFIXVIBESEND ZXCVFIXVIBESEG7 未经身份验证的远程攻击者可能会在所需的配置条件下触发 NGINX Worker 中的堆溢出,导致 Worker 重新启动并可能中断服务。代码执行还取决于地址空间布局随机化 (ASLR) 被禁用或绕过 CVE-2026-42055ZXCVFIXVIBETOKEN1ZXCV。 ZXCVFIXVIBESEND ZXCVFIXVIBESEG8 F5 分配 CVSS v3.1 8.1(高),具有高攻击复杂性,而 nginx.org 将咨询标记为 Medium CVE-2026-42055ZXCVFIXVIBETOKEN1ZXCVZXCVFIXVIBETOKEN2ZXCV。这些是单独发布的评级系统,因此 ZXCVFIXVIBETOKEN3ZXCV 均提供归因,而不是将任一标签视为通用标签。 ZXCVFIXVIBESEND ZXCVFIXVIBESEG9 ## CVE-2026-42055 如何覆盖它 ZXCVFIXVIBESEND ZXCVFIXVIBESEG10 当存储库可见证据将官方 NGINX 开源容器映像的确切受影响版本链接到供应商 CVE-2026-42055ZXCVFIXVIBETOKEN1ZXCV 描述的异常上游代理配置时,ZXCVFIXVIBETOKEN2ZXCV ZXCVFIXVIBETOKEN3ZXCV 存储库扫描以中等置信度报告**可能的问题**。该发现确定了相关的映像/版本和配置位置,提供了固定发布指南,并将经过验证的存储库证据与未经验证的运行时状态区分开来。 ZXCVFIXVIBESEND ZXCVFIXVIBESEG11 报道有意保守。它目前专注于基于 Dockerfile 的组件,这些组件使用官方 NGINX 开源镜像和存储库提供的配置。它不声明覆盖 NGINX Plus、分发包、自定义或私有映像、浮动版本标签、存储库外部组装的配置或部署的运行时。发现并不能证明工件已部署、可访问或可利用,并且任何发现都不能保证每个运行时不受影响。 ZXCVFIXVIBESEND ZXCVFIXVIBESEG12 CVE-2026-42055 不会运行 NGINX、发送危险标头流量、崩溃测试工作人员、检查 ASLR 或尝试内存损坏或代码执行。确认这些行为将跨越安全扫描边界。 ZXCVFIXVIBESEND ZXCVFIXVIBESEG13 ## 修复

CVE-2026-42055 is a conditional heap-based buffer overflow in NGINX HTTP/2 and gRPC upstream proxying. F5 scores it 8.1 High under CVSS v3.1, while nginx.org classifies it Medium. Exploitation requires several uncommon configuration prerequisites, including oversized client-header buffers; worker restart is the direct documented impact, and code execution additionally requires ASLR to be disabled or bypassed. FixVibe reports conservative repository evidence for affected official NGINX Open Source container deployments and does not perform hazardous active proof.

CVE-2026-42055CWE-122CWE-787CWE-131

CVE-2026-42055 is a heap-based buffer overflow in the NGINX modules used for upstream HTTP/2 and gRPC proxying. It is conditional, not a blanket vulnerability in every NGINX deployment: the affected proxy behavior, disabled invalid-header filtering, and oversized non-default client-header buffers must all be present [S1][S4].

Affected configurations and versions

The vendor record covers NGINX Open Source and NGINX Plus only when all documented configuration prerequisites coincide [S1][S4]. For NGINX Open Source, the affected published releases are 1.13.10 through 1.30.2, plus 1.31.0 and 1.31.1; nginx.org identifies 1.30.3+ stable and 1.31.2+ mainline as not vulnerable [S2][S3]. F5's CNA record also lists NGINX Plus R37 37.0 releases before 37.0.2.1 and R36 releases before R36 P6 as affected; versions past End of Technical Support were not evaluated [S1][S4].

Impact and severity

A remote unauthenticated attacker could trigger a heap overflow in an NGINX worker under the required configuration conditions, causing the worker to restart and potentially disrupting service. Code execution is additionally conditional on Address Space Layout Randomization (ASLR) being disabled or bypassed [S1][S4].

F5 assigns CVSS v3.1 8.1 (High), with High attack complexity, while nginx.org labels the advisory Medium [S1][S2][S4]. These are separate published rating systems, so FixVibe presents both with attribution rather than treating either label as universal.

How FixVibe covers it

FixVibe GitHub repository scans report a Likely issue with medium confidence when repository-visible evidence links an exact affected release of the official NGINX Open Source container image to the unusual upstream proxy configuration described by the vendor [S1][S4]. The finding identifies the relevant image/version and configuration locations, provides fixed-release guidance, and distinguishes verified repository evidence from unverified runtime state.

Coverage is intentionally conservative. It currently focuses on Dockerfile-based components that use the official NGINX Open Source image and repository-supplied configuration. It does not claim coverage for NGINX Plus, distribution packages, custom or private images, floating version tags, configuration assembled outside the repository, or the deployed runtime. A finding does not prove that the artifact is deployed, reachable, or exploitable, and no finding is not a guarantee that every runtime is unaffected.

FixVibe does not run NGINX, send hazardous header traffic, crash-test workers, inspect ASLR, or attempt memory corruption or code execution. Confirming those behaviors would cross a safe scanning boundary.

Remediation

升级到固定的、受支持的版本。对于 NGINX 开源,请使用 1.30.3 或 1.31.2,或更新的受支持版本; NGINX Plus 用户应应用相应的 F5 支持的补丁级别 [S1][S2][S3][S4]。固定更正的映像版本,重建它,然后重新部署每个受影响的组件。 ZXCVFIXVIBESEND ZXCVFIXVIBESEG1 还要查看完整的有效配置。保持启用无效标头验证,避免过大的客户端标头缓冲区设置(除非操作上需要),并在不必要时停止使用上游 HTTP/2 或 gRPC 代理。使用 [S1] 验证正在运行的版本,使用 [S2] 检查有效配置,运行 [S3],并在重新运行 [S4] 存储库扫描之前仅执行良性 HTTP/2 和 gRPC 冒烟测试。不要使用导致崩溃或内存损坏的流量来验证修复。

Review the complete effective configuration as well. Keep invalid-header validation enabled, avoid oversized client-header buffer settings unless they are operationally required, and stop using upstream HTTP/2 or gRPC proxying where it is unnecessary. Verify the running version with nginx -v, review the effective configuration with nginx -T, run nginx -t, and exercise only benign HTTP/2 and gRPC smoke tests before rerunning the FixVibe repository scan. Do not validate the fix with crash-inducing or memory-corruption traffic.

有条件 NGINX HTTP/2 和 gRPC 代理缓冲区溢出 (CVE-2026-42055) ZXCVFIXVIBESEND ZXCVFIXVIBESEG1 CVE-2026-42055 影响特定 NGINX HTTP/2 和 gRPC 代理配置。查看所需条件、已修复版本、影响和 ZXCVFIXVIBETOKEN1ZXCV 覆盖范围。 ZXCVFIXVIBESEND ZXCVFIXVIBESEG2 CVE-2026-42055 是 NGINX HTTP/2 和 gRPC 上游代理中基于条件堆的缓冲区溢出。 F5 在 CVSS v3.1 下的得分为 8.1 高,而 nginx.org 将其分类为中。利用该漏洞需要几个不常见的配置先决条件,包括超大的客户端标头缓冲区;工作进程重启是直接记录的影响,并且代码执行还需要禁用或绕过 ASLR。 ZXCVFIXVIBETOKEN1ZXCV 报告受影响的官方 NGINX 开源容器部署的保守存储库证据,并且不执行危险的主动证明。 ZXCVFIXVIBESEND ZXCVFIXVIBESEG3 ZXCVFIXVIBETOKEN2ZXCV 是用于上游 HTTP/2 和 gRPC 代理的 NGINX 模块中基于堆的缓冲区溢出。这是有条件的,而不是每个 NGINX 部署中的全面漏洞:受影响的代理行为、禁用的无效标头过滤和超大的非默认客户端标头缓冲区都必须存在 CVE-2026-42055ZXCVFIXVIBETOKEN1ZXCV。 ZXCVFIXVIBESEND ZXCVFIXVIBESEG4 ## 受影响的配置和版本 ZXCVFIXVIBESEND ZXCVFIXVIBESEG5 仅当所有记录的配置先决条件符合 CVE-2026-42055ZXCVFIXVIBETOKEN1ZXCV 时,供应商记录才涵盖 NGINX Open Source 和 NGINX Plus。对于 NGINX Open Source,受影响的已发布版本为 1.13.10 至 1.30.2,以及 1.31.0 和 1.31.1; nginx.org 将 1.30.3+ 稳定版和 1.31.2+ 主线识别为不易受攻击的 ZXCVFIXVIBETOKEN2ZXCVZXCVFIXVIBETOKEN3ZXCV。 F5 的 CNA 记录还列出了 37.0.2.1 之前的 NGINX Plus R37 37.0 版本以及 R36 P6 之前的 R36 版本受到影响;技术支持结束后的版本未进行评估 ZXCVFIXVIBETOKEN4ZXCVZXCVFIXVIBETOKEN5ZXCV。 ZXCVFIXVIBESEND ZXCVFIXVIBESEG6 ## 影响和严重性 ZXCVFIXVIBESEND ZXCVFIXVIBESEG7 未经身份验证的远程攻击者可能会在所需的配置条件下触发 NGINX Worker 中的堆溢出,导致 Worker 重新启动并可能中断服务。代码执行还取决于地址空间布局随机化 (ASLR) 被禁用或绕过 CVE-2026-42055ZXCVFIXVIBETOKEN1ZXCV。 ZXCVFIXVIBESEND ZXCVFIXVIBESEG8 F5 分配 CVSS v3.1 8.1(高),具有高攻击复杂性,而 nginx.org 将咨询标记为 Medium CVE-2026-42055ZXCVFIXVIBETOKEN1ZXCVZXCVFIXVIBETOKEN2ZXCV。这些是单独发布的评级系统,因此 ZXCVFIXVIBETOKEN3ZXCV 均提供归因,而不是将任一标签视为通用标签。 ZXCVFIXVIBESEND ZXCVFIXVIBESEG9 ## CVE-2026-42055 如何覆盖它 ZXCVFIXVIBESEND ZXCVFIXVIBESEG10 当存储库可见证据将官方 NGINX 开源容器映像的确切受影响版本链接到供应商 CVE-2026-42055ZXCVFIXVIBETOKEN1ZXCV 描述的异常上游代理配置时,ZXCVFIXVIBETOKEN2ZXCV ZXCVFIXVIBETOKEN3ZXCV 存储库扫描以中等置信度报告**可能的问题**。该发现确定了相关的映像/版本和配置位置,提供了固定发布指南,并将经过验证的存储库证据与未经验证的运行时状态区分开来。 ZXCVFIXVIBESEND ZXCVFIXVIBESEG11 报道有意保守。它目前专注于基于 Dockerfile 的组件,这些组件使用官方 NGINX 开源镜像和存储库提供的配置。它不声明覆盖 NGINX Plus、分发包、自定义或私有映像、浮动版本标签、存储库外部组装的配置或部署的运行时。发现并不能证明工件已部署、可访问或可利用,并且任何发现都不能保证每个运行时不受影响。 ZXCVFIXVIBESEND ZXCVFIXVIBESEG12 CVE-2026-42055 不会运行 NGINX、发送危险标头流量、崩溃测试工作人员、检查 ASLR 或尝试内存损坏或代码执行。确认这些行为将跨越安全扫描边界。 ZXCVFIXVIBESEND ZXCVFIXVIBESEG13 ## 修复 — FixVibe research · FixVibe