vulnerability Unpatched XRING Flaw in XQUIC Lets Remote Clients Crash HTTP/3 Servers A remote client can crash HTTP/3 servers running XQUIC, Alibaba's HTTP/3 and QUIC library. The vulnerability, dubbed XRING, stems from an incorrect size calculation during table resizing within the QPACK header compression mechanism. No patch is available, and the issue affects all versions through v1.9.4. While no exp… The Hacker News · Jul 10, 2026 High CVE-2026-42530httphttp3quic
vulnerability F5 Patches Two Critical NGINX Open Source Flaws Enabling Remote Code Execution F5 has released security patches to address two critical vulnerabilities (CVE-2026-42530 and CVE-2026-42055) in its NGINX Open Source and NGINX Plus products. These vulnerabilities, which allow for remote code execution,… The Hacker News · Jun 18, 2026 Critical CVE-2026-42530CVE-2026-42055CVE-2026-42945nginxcode executionremote vulnerability
vulnerability F5 issues out-of-band patches for critical NGINX vulnerabilities Cybersecurity company F5 has released out-of-band security updates to address multiple NGINX web server vulnerabilities, including two critical-severity flaws that could allow attackers to execute code on vulnerable syst… BleepingComputer · Jun 18, 2026 CVE-2026-42530CVE-2026-42055CVE-2026-11311
vulnerability F5 Patches Critical, High-Severity NGINX Vulnerabilities Critical flaws in NGINX could allow remote, unauthenticated attackers to cause a restart and potentially execute arbitrary code. The post F5 Patches Critical, High-Severity NGINX Vulnerabilities appeared first on Securit… SecurityWeek · Jun 18, 2026 Critical CVE-2026-42530CVE-2026-42055CVE-2026-11311