CVE-2026-42926
Published: May 15, 2026Last modified: May 15, 2026
Description
When NGINX Open Source is configured to proxy HTTP/2 traffic by setting proxy_http_version to 2, and also uses proxy_set_body, an attacker may be able to inject frame headers and payload bytes to the upstream peer. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Severity score breakdown
| Parameter | Value |
|---|---|
| Base score | 5.8 |
| Attack Vector | NETWORK |
| Attack complexity | LOW |
| Privileges required | NONE |
| User interaction | NONE |
| Scope | CHANGED |
| Confidentiality | NONE |
| Integrity impact | LOW |
| Availability impact | NONE |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N |
Notes
Introduced in 1.29.4 according to https://nginx.org/en/security_advisories.html
Status
| Product | Release | Package | Status |
|---|---|---|---|
| Alpaquita Linux | 23 LTS | nginx | Not affected (1.22.1-r4) |
| 25 LTS | nginx | Not affected (1.28.3-r0) |