← Back

CVE-2026-40460

nvd nist
Published: May 13, 2026Modified: Jun 29, 2026

JSON object

Loading...
6.9
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Show more
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: f5sirt@f5.com (Secondary)

Description

When NGINX Plus or NGINX Open Source are configured to use the HTTP/3 QUIC module, an attacker may be able to spoof their source IP address allowing for bypass of authorization or bypass of rate limiting.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected (13)

7 products
Dos
Nginx Gateway Fabric
Nginx Ingress Controller
Nginx Instance Manager
Nginx Open Source
Nginx Plus
Waf
Configuration A
13 vulnerable
Vulnerable SoftwareAffected Versions
F5
From 4.3.0 to 4.7.0
Version 4.8.0
F5
From 1.3.0 to 1.6.2
From 2.0.0 to 2.6.0
F5
From 3.5.0 to 3.7.2
From 4.0.0 to 4.0.1
From 5.0.0 to 5.4.2
From 2.16.0 to 2.22.0
From 1.25.0 to 1.30.0
From r32 to r36
F5
From 4.9.0 to 4.16.0
From 5.1.0 to 5.8.0
From 5.9.0 to 5.12.1

References (1)

Source: f5sirt@f5.com
Vendor Advisory

Timeline

No history available yet.