Live data from Hacker News

CVE-2026-42530: Nginx 1.30.2 and Nginx 1.31.2

cve.org

1–3 of 3 posts

Re: CVE-2026-42530: Nginx 1.30.2 and Nginx 1.31.2

#2
> When NGINX Open Source is configured to use the HTTP/3 QUIC module, a remote unauthenticated attacker along with conditions beyond their control can use a specially crafted HTTP/3 session to reopen a QPACK encoder stream.

Emphasis is mine. How much heavy lifting is this phrase doing?

Re: CVE-2026-42530: Nginx 1.30.2 and Nginx 1.31.2

#3

> When NGINX Open Source is configured to use the HTTP/3 QUIC module, a remote unauthenticated attacker along with conditions beyond their control can use a specially crafted HTTP/3 session to reopen a QPACK encoder stream. Emphasis is mine. How much heavy lifting is this phrase doing?

Definitely interested in this as well.