Tracker / CVE-2024-31079
CVE-2024-31079
Medium 4.8
When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 requests can cause NGINX worker processes to terminate or cause other potential impact. This attack requires that a request be specifically timed during the connection draining process, which the attacker has no visibility and limited influence over.
Affected products and versions
| f5 | nginx_open_source · 1.25.0 → 1.26.1 |
|---|---|
| f5 | nginx_plus |
| fedoraproject | fedora |
Analysis
This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.