Bugzilla – Bug 1225624
VUL-0: CVE-2024-32760: nginx: undisclosed HTTP/3 encoder instructions can cause NGINX worker processes to terminate
Last modified: 2024-05-29 19:15:03 UTC
When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 encoder instructions can cause NGINX worker processes to terminate or cause or other potential impact. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-32760 https://www.cve.org/CVERecord?id=CVE-2024-32760 https://my.f5.com/manage/s/article/K000139609
As per [0], it would appear that only versions 1.25.0 and above (until version 1.26.1) are affected by this issue. [0] https://nginx.org/en/docs/quic.html