F5 Product Security Update Advisory (CVE-2026-42530)

F5 Product Security Update Advisory (CVE-2026-42530)
  • A security update has been released for CVE-2026-42530, a vulnerability discovered in F5 products.
  • The vulnerability is a use-after-free vulnerability in the NGINX ngxhttpv3_module.
  • The affected products are as follows:
    • NGINX Open Source 1.31.0 through 1.31.1.
    • NGINX Instance Manager 2.17.0 through 2.22.0.
    • NGINX Gateway Fabric 2.0.0 through 2.6.3.
    • NGINX Gateway Fabric 1.3.0 through 1.6.2.
    • NGINX Ingress Controller 5.0.0 through 5.5.0.
    • NGINX Ingress Controller 4.0.0 through 4.0.1.
    • NGINX Ingress Controller 3.5.0 or later, up to and including 3.7.2.
  • The patched versions provided are NGINX Open Source 1.31.2 and NGINX Gateway Fabric 2.6.4.
  • For certain versions of NGINX Instance Manager, NGINX Gateway Fabric, and NGINX Ingress Controller, users were advised to update to the latest version with the Vulnerability Patch as per the instructions on the reference site.
  • The reference site provided is K000161616, the document titled NGINX ngxhttpv3_module vulnerability CVE-2026-42530.