{"id":"CVE-2026-42926","details":"When NGINX Open Source is configured to proxy HTTP/2 traffic by setting proxy_http_version to 2, and also uses proxy_set_body, an attacker may be able to inject frame headers and payload bytes to the upstream peer.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.","aliases":["BIT-nginx-2026-42926","BIT-nginx-gateway-2026-42926"],"modified":"2026-06-26T03:55:23.843185791Z","published":"2026-05-13T16:16:49.640Z","related":["openSUSE-SU-2026:10796-1"],"database_specific":{"unresolved_ranges":[{"source":"CPE_RANGE","cpes":["cpe:2.3:a:f5:nginx_instance_manager:*:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"2.16.0"},{"last_affected":"2.22.0"}],"vendor_product":"f5:nginx_instance_manager"}]},"references":[{"type":"ADVISORY","url":"https://my.f5.com/manage/s/article/K000161131"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/nginx/kubernetes-ingress","events":[{"introduced":"33971b8ff54bc55785a7b38c07a21e03bda25080"},{"last_affected":"561824f3077b7615c2fa764bd6d8e7a47e184857"},{"introduced":"81bae7d0360fdf277b2d3e355d02e410ee211ef8"},{"last_affected":"43349033e28d0b6aa38773ff840deba079654a4f"},{"introduced":"8dfabca757830d0821e86206c2db83044e6696f0"},{"last_affected":"cd864d71a5e3b6698b80daee02b2785c4020db10"}],"database_specific":{"source":"CPE_RANGE","cpe":"cpe:2.3:a:f5:nginx_ingress_controller:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"3.5.0"},{"last_affected":"3.7.2"},{"introduced":"4.0.0"},{"last_affected":"4.0.1"},{"introduced":"5.0.0"},{"last_affected":"5.4.2"}]}}],"versions":["v4.0.1","v4.0.0"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-42926.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/nginx/nginx","events":[{"introduced":"c70457482c4223b6fd9adc3caa6a302163e6030d"},{"last_affected":"6e14e954aaacce9a433d9b07b4653809c7594ab8"}],"database_specific":{"source":"CPE_RANGE","cpe":"cpe:2.3:a:f5:nginx_open_source:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"1.29.4"},{"last_affected":"1.30.0"}]}}],"versions":["release-1.30.0","release-1.29.8","release-1.29.7","release-1.29.6","release-1.29.5","release-1.29.4"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-42926.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/nginx/nginx-gateway-fabric","events":[{"introduced":"3a372747333fb1db372af7cf0b18ed7eef7c91f7"},{"last_affected":"532db6a20b2912fe397211eef9f8d564d46a4bdd"},{"introduced":"7dad8b31e3f0c3eadce36fed8c276e83e6583d24"},{"last_affected":"95a66d8cec0ce98e1985aeab728317c5ba7ec0c6"}],"database_specific":{"source":"CPE_RANGE","cpe":"cpe:2.3:a:f5:nginx_gateway_fabric:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"1.3.0"},{"last_affected":"1.6.2"},{"introduced":"2.0.0"},{"last_affected":"2.6.0"}]}}],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-42926.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"}]}