216.73.217.22

CVE-2026-40460

· Published 13/05/2026 16:16 · Modified 13/05/2026 16:27

Labels: CVE-2026-40460 2026-05-13CVE-2026-40460CWE-290[email protected]

Essential information

Published
13/05/2026 16:16
Modified
13/05/2026 16:27
Author
Creator
CVSS
6.9 MEDIUM (v3) 6.9 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

When NGINX Plus or NGINX Open Source are configured to use the HTTP/3 QUIC module, an attacker may be able to spoof their source IP address allowing for bypass of authorization or bypass of rate limiting.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

NVD status

Status
Awaiting Analysis — CVE has been marked for Analysis. Normally once in this state the CVE will be analyzed by NVD staff within 24 hours.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
f5 / nginx plus cpe:2.3:a:f5:nginx_plus:*:*:*:*:*:*:*:*
f5 / nginx open source cpe:2.3:a:f5:nginx_open_source:*:*:*:*:*:*:*:*

References