FixVibe
覆蓋FixVibehigh

有條件 NGINX HTTP/2 和 gRPC 代理緩衝區溢位 (CVE-2026-42055) ZXCVFIXVIBESEND ZXCVFIXVIBESEG1 CVE-2026-42055 影響特定 NGINX HTTP/2 和 gRPC 代理程式配置。查看所需條件、已修復版本、影響和 ZXCVFIXVIBETOKEN1ZXCV 覆蓋範圍。 ZXCVFIXVIBESEND ZXCVFIXVIBESEG2 CVE-2026-42055 是 NGINX HTTP/2 和 gRPC 上游代理程式中基於條件堆的緩衝區溢位。 F5 在 CVSS v3.1 下的得分為 8.1 高,而 nginx.org 將其分類為中。利用該漏洞需要幾個不常見的配置先決條件,包括超大的客戶端標頭緩衝區;工作進程重新啟動是直接記錄的影響,且程式碼執行還需要停用或繞過 ASLR。 ZXCVFIXVIBETOKEN1ZXCV 報告受影響的官方 NGINX 開源容器部署的保守儲存庫證據,並且不執行危險的主動證明。 ZXCVFIXVIBESEND ZXCVFIXVIBESEG3 ZXCVFIXVIBETOKEN2ZXCV 是用於上游 HTTP/2 和 gRPC 代理的 NGINX 模組中基於堆疊的緩衝區溢位。這是有條件的,而不是每個 NGINX 部署中的全面漏洞:受影響的代理行為、禁用的無效標頭過濾和超大的非預設客戶端標頭緩衝區都必須存在 CVE-2026-42055ZXCVFIXVIBETOKEN1ZXCV。 ZXCVFIXVIBESEND ZXCVFIXVIBESEG4 ## 受影響的配置和版本 ZXCVFIXVIBESEND ZXCVFIXVIBESEG5 只有當所有記錄的配置先決條件符合 CVE-2026-42055ZXCVFIXVIBETOKEN1ZXCV 時,供應商記錄才涵蓋 NGINX Open Source 和 NGINX Plus。對於 NGINX Open Source,受影響的已發布版本為 1.13.10 至 1.30.2,以及 1.31.0 和 1.31.1; nginx.org 將 1.30.3+ 穩定版和 1.31.2+ 主線識別為不易攻擊性的 ZCVX7VIZ7ENZ747444HIXCVCV。 F5 的 CNA 記錄還列出了 37.0.2.1 之前的 NGINX Plus R37 37.0 版本以及 R36 P6 之前的 R36 版本受到影響;技術支援結束後的版本未進行評估 ZXCVFIXVIBETOKEN4ZXCVZXCVFIXVIBETOKEN5ZX。 ZXCVFIXVIBESEND ZXCVFIXVIBESEG6 ## 影響和嚴重性 ZXCVFIXVIBESEND ZXCVFIXVIBESEG7 未經身份驗證的遠端攻擊者可能會在所需的配置條件下觸發 NGINX Worker 中的堆溢出,導致 Worker 重新啟動並可能中斷服務。程式碼執行也取決於位址空間佈局隨機化 (ASLR) 被停用或繞過 CVE-2026-42055ZXCVFIXVIBETOKEN1ZXCV。 ZXCVFIXVIBESEND ZXCVFIXVIBESEG8 F5 分配 CVSS v3.1 8.1(高),具有高攻擊複雜性,而 nginx.org 將諮詢標記為 Medium CVE-2026-42055ZXCVFIXVIBETOKEN1ZXCVZXCVFIXVIBETOKEN2ZXCV。這些是單獨發布的評級系統,因此 ZXCVFIXVIBETOKEN3ZXCV 均提供歸因,而不是將任一標籤視為通用標籤。 ZXCVFIXVIBESEND ZXCVFIXVIBESEG9 ## CVE-2026-42055 如何涵蓋它 ZXCVFIXVIBESEND ZXCVFIXVIBESEG10 當儲存庫可見證據將官方 NGINX 開源容器映像的確切受影響版本連結到供應商 CVE-2026-42055ZXCVFIXVIBETOKEN1ZXCV 所描述的異常上游代理配置時,ZXCVFIXVIBETOKEN2ZXCV ZXCVFIXVIBETOKEN3ZXCVAIXVIBETOKEN2ZXCV ZXCVFIXVIBETOKEN3ZX 儲存庫可能掃描的中度問題。該發現確定了相關的映像/版本和配置位置,提供了固定發布指南,並將經過驗證的儲存庫證據與未經驗證的運行時狀態區分開來。 ZXCVFIXVIBESEND ZXCVFIXVIBESEG11 報道有意保守。它目前專注於基於 Dockerfile 的元件,這些元件使用官方 NGINX 開源映像檔和儲存庫提供的配置。它不聲明覆蓋 NGINX Plus、分發包、自訂或私人映像、浮動版本標籤、儲存庫外部組裝的配置或部署的執行時間。發現並不能證明工件已部署、可存取或可利用,且任何發現都不能保證每個執行時間不受影響。 ZXCVFIXVIBESEND ZXCVFIXVIBESEG12 CVE-2026-42055 不會執行 NGINX、發送危險標頭流量、崩潰測試工作人員、檢查 ASLR 或嘗試記憶體損壞或程式碼執行。確認這些行為將跨越安全掃描邊界。 ZXCVFIXVIBESEND ZXCVFIXVIBESEG13 ## 修復

CVE-2026-42055 is a conditional heap-based buffer overflow in NGINX HTTP/2 and gRPC upstream proxying. F5 scores it 8.1 High under CVSS v3.1, while nginx.org classifies it Medium. Exploitation requires several uncommon configuration prerequisites, including oversized client-header buffers; worker restart is the direct documented impact, and code execution additionally requires ASLR to be disabled or bypassed. FixVibe reports conservative repository evidence for affected official NGINX Open Source container deployments and does not perform hazardous active proof.

CVE-2026-42055CWE-122CWE-787CWE-131

CVE-2026-42055 is a heap-based buffer overflow in the NGINX modules used for upstream HTTP/2 and gRPC proxying. It is conditional, not a blanket vulnerability in every NGINX deployment: the affected proxy behavior, disabled invalid-header filtering, and oversized non-default client-header buffers must all be present [S1][S4].

Affected configurations and versions

The vendor record covers NGINX Open Source and NGINX Plus only when all documented configuration prerequisites coincide [S1][S4]. For NGINX Open Source, the affected published releases are 1.13.10 through 1.30.2, plus 1.31.0 and 1.31.1; nginx.org identifies 1.30.3+ stable and 1.31.2+ mainline as not vulnerable [S2][S3]. F5's CNA record also lists NGINX Plus R37 37.0 releases before 37.0.2.1 and R36 releases before R36 P6 as affected; versions past End of Technical Support were not evaluated [S1][S4].

Impact and severity

A remote unauthenticated attacker could trigger a heap overflow in an NGINX worker under the required configuration conditions, causing the worker to restart and potentially disrupting service. Code execution is additionally conditional on Address Space Layout Randomization (ASLR) being disabled or bypassed [S1][S4].

F5 assigns CVSS v3.1 8.1 (High), with High attack complexity, while nginx.org labels the advisory Medium [S1][S2][S4]. These are separate published rating systems, so FixVibe presents both with attribution rather than treating either label as universal.

How FixVibe covers it

FixVibe GitHub repository scans report a Likely issue with medium confidence when repository-visible evidence links an exact affected release of the official NGINX Open Source container image to the unusual upstream proxy configuration described by the vendor [S1][S4]. The finding identifies the relevant image/version and configuration locations, provides fixed-release guidance, and distinguishes verified repository evidence from unverified runtime state.

Coverage is intentionally conservative. It currently focuses on Dockerfile-based components that use the official NGINX Open Source image and repository-supplied configuration. It does not claim coverage for NGINX Plus, distribution packages, custom or private images, floating version tags, configuration assembled outside the repository, or the deployed runtime. A finding does not prove that the artifact is deployed, reachable, or exploitable, and no finding is not a guarantee that every runtime is unaffected.

FixVibe does not run NGINX, send hazardous header traffic, crash-test workers, inspect ASLR, or attempt memory corruption or code execution. Confirming those behaviors would cross a safe scanning boundary.

Remediation

升級到固定的、支援的版本。對於 NGINX 開源,請使用 1.30.3 或 1.31.2,或更新的支援版本;NGINX Plus 使用者應套用對應的 F5 支援的修補程式等級 [S1][S2]ZXCVFIXTOKEN0ZXCVZXCVAEN2XKEN1ZXCVXCVFIXFIXTOKEN2XVIZ77444444469776836666666CCxVIp固定更正的映像版本,重建它,然後重新部署每個受影響的元件。 ZXCVFIXVIBESEND ZXCVFIXVIBESEG1 也要查看完整的有效配置。保持啟用無效標頭驗證,避免過大的客戶端標頭緩衝區設定(除非操作上需要),並在不必要時停止使用上游 HTTP/2 或 gRPC 代理。使用 [S1] 驗證正在運行的版本,使用 [S2] 檢查有效配置,運行 [S3],並在重新運行 [S4] 儲存庫掃描之前僅執行良性 HTTP/2 和 gRPC 測試。不要使用導致崩潰或記憶體損壞的流量來驗證修復。

Review the complete effective configuration as well. Keep invalid-header validation enabled, avoid oversized client-header buffer settings unless they are operationally required, and stop using upstream HTTP/2 or gRPC proxying where it is unnecessary. Verify the running version with nginx -v, review the effective configuration with nginx -T, run nginx -t, and exercise only benign HTTP/2 and gRPC smoke tests before rerunning the FixVibe repository scan. Do not validate the fix with crash-inducing or memory-corruption traffic.

有條件 NGINX HTTP/2 和 gRPC 代理緩衝區溢位 (CVE-2026-42055) ZXCVFIXVIBESEND ZXCVFIXVIBESEG1 CVE-2026-42055 影響特定 NGINX HTTP/2 和 gRPC 代理程式配置。查看所需條件、已修復版本、影響和 ZXCVFIXVIBETOKEN1ZXCV 覆蓋範圍。 ZXCVFIXVIBESEND ZXCVFIXVIBESEG2 CVE-2026-42055 是 NGINX HTTP/2 和 gRPC 上游代理程式中基於條件堆的緩衝區溢位。 F5 在 CVSS v3.1 下的得分為 8.1 高,而 nginx.org 將其分類為中。利用該漏洞需要幾個不常見的配置先決條件,包括超大的客戶端標頭緩衝區;工作進程重新啟動是直接記錄的影響,且程式碼執行還需要停用或繞過 ASLR。 ZXCVFIXVIBETOKEN1ZXCV 報告受影響的官方 NGINX 開源容器部署的保守儲存庫證據,並且不執行危險的主動證明。 ZXCVFIXVIBESEND ZXCVFIXVIBESEG3 ZXCVFIXVIBETOKEN2ZXCV 是用於上游 HTTP/2 和 gRPC 代理的 NGINX 模組中基於堆疊的緩衝區溢位。這是有條件的,而不是每個 NGINX 部署中的全面漏洞:受影響的代理行為、禁用的無效標頭過濾和超大的非預設客戶端標頭緩衝區都必須存在 CVE-2026-42055ZXCVFIXVIBETOKEN1ZXCV。 ZXCVFIXVIBESEND ZXCVFIXVIBESEG4 ## 受影響的配置和版本 ZXCVFIXVIBESEND ZXCVFIXVIBESEG5 只有當所有記錄的配置先決條件符合 CVE-2026-42055ZXCVFIXVIBETOKEN1ZXCV 時,供應商記錄才涵蓋 NGINX Open Source 和 NGINX Plus。對於 NGINX Open Source,受影響的已發布版本為 1.13.10 至 1.30.2,以及 1.31.0 和 1.31.1; nginx.org 將 1.30.3+ 穩定版和 1.31.2+ 主線識別為不易攻擊性的 ZCVX7VIZ7ENZ747444HIXCVCV。 F5 的 CNA 記錄還列出了 37.0.2.1 之前的 NGINX Plus R37 37.0 版本以及 R36 P6 之前的 R36 版本受到影響;技術支援結束後的版本未進行評估 ZXCVFIXVIBETOKEN4ZXCVZXCVFIXVIBETOKEN5ZX。 ZXCVFIXVIBESEND ZXCVFIXVIBESEG6 ## 影響和嚴重性 ZXCVFIXVIBESEND ZXCVFIXVIBESEG7 未經身份驗證的遠端攻擊者可能會在所需的配置條件下觸發 NGINX Worker 中的堆溢出,導致 Worker 重新啟動並可能中斷服務。程式碼執行也取決於位址空間佈局隨機化 (ASLR) 被停用或繞過 CVE-2026-42055ZXCVFIXVIBETOKEN1ZXCV。 ZXCVFIXVIBESEND ZXCVFIXVIBESEG8 F5 分配 CVSS v3.1 8.1(高),具有高攻擊複雜性,而 nginx.org 將諮詢標記為 Medium CVE-2026-42055ZXCVFIXVIBETOKEN1ZXCVZXCVFIXVIBETOKEN2ZXCV。這些是單獨發布的評級系統,因此 ZXCVFIXVIBETOKEN3ZXCV 均提供歸因,而不是將任一標籤視為通用標籤。 ZXCVFIXVIBESEND ZXCVFIXVIBESEG9 ## CVE-2026-42055 如何涵蓋它 ZXCVFIXVIBESEND ZXCVFIXVIBESEG10 當儲存庫可見證據將官方 NGINX 開源容器映像的確切受影響版本連結到供應商 CVE-2026-42055ZXCVFIXVIBETOKEN1ZXCV 所描述的異常上游代理配置時,ZXCVFIXVIBETOKEN2ZXCV ZXCVFIXVIBETOKEN3ZXCVAIXVIBETOKEN2ZXCV ZXCVFIXVIBETOKEN3ZX 儲存庫可能掃描的中度問題。該發現確定了相關的映像/版本和配置位置,提供了固定發布指南,並將經過驗證的儲存庫證據與未經驗證的運行時狀態區分開來。 ZXCVFIXVIBESEND ZXCVFIXVIBESEG11 報道有意保守。它目前專注於基於 Dockerfile 的元件,這些元件使用官方 NGINX 開源映像檔和儲存庫提供的配置。它不聲明覆蓋 NGINX Plus、分發包、自訂或私人映像、浮動版本標籤、儲存庫外部組裝的配置或部署的執行時間。發現並不能證明工件已部署、可存取或可利用,且任何發現都不能保證每個執行時間不受影響。 ZXCVFIXVIBESEND ZXCVFIXVIBESEG12 CVE-2026-42055 不會執行 NGINX、發送危險標頭流量、崩潰測試工作人員、檢查 ASLR 或嘗試記憶體損壞或程式碼執行。確認這些行為將跨越安全掃描邊界。 ZXCVFIXVIBESEND ZXCVFIXVIBESEG13 ## 修復 — FixVibe research · FixVibe