imPC@ndo IT

Tracker / CVE-2024-31079

CVE-2024-31079

Medium 4.8

When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 requests can cause NGINX worker processes to terminate or cause other potential impact. This attack requires that a request be specifically timed during the connection draining process, which the attacker has no visibility and limited influence over.

Affected products and versions

f5 nginx_open_source · 1.25.0 → 1.26.1
f5 nginx_plus
fedoraproject fedora

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References