<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic NGINX CVE-2026-42530: Check Point-Managed and Self-Managed NGINX Deployments Not Affected in WAF</title>
    <link>https://community.checkpoint.com/t5/WAF/NGINX-CVE-2026-42530-Check-Point-Managed-and-Self-Managed-NGINX/m-p/278992#M414</link>
    <description>&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Description&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;A recently disclosed vulnerability, CVE-2026-42530 (&lt;/SPAN&gt;&lt;A href="https://www.cve.org/CVERecord?id=CVE-2026-42530" target="_blank"&gt;&lt;SPAN data-contrast="none"&gt;https://www.cve.org/CVERecord?id=CVE-2026-42530&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;), affects the NGINX ngx_http_v3_module used for HTTP/3.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;According to public reporting, this use-after-free condition can be triggered when NGINX uses the HTTP/3 QUIC module and a remote, unauthenticated attacker sends a crafted HTTP/3 session to reopen a QPACK encoder stream, corrupting memory in the worker process. The result is worker restarts and denial-of-service and, where ASLR is disabled or can be bypassed, possible code execution. The issue affects NGINX Open Source 1.31.0 and 1.31.1 only and was patched in 1.31.2. HTTP/3 must be explicitly enabled and is not on by default. Vendor advisory: K000161616 (&lt;/SPAN&gt;&lt;A href="https://my.f5.com/manage/s/article/K000161616" target="_blank"&gt;&lt;SPAN data-contrast="none"&gt;https://my.f5.com/manage/s/article/K000161616&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;).&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Check Point Statement Regarding NGINX Vulnerability CVE-2026-42530&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Following internal assessment and validation, Check Point confirms that Check Point WAF is not affected by CVE-2026-42530.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;The vulnerability is limited to NGINX Open Source versions 1.31.0 and 1.31.1. Check Point WAF does not run an NGINX version within this affected range, so the vulnerable code path is not present.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;All Check Point-managed NGINX deployments, including Check Point WAF SaaS, AppSec Gateway, and Single (Unified) Container, are not vulnerable to this issue.&amp;nbsp;Check Point WAF deployments&amp;nbsp;with&amp;nbsp;self-managed&amp;nbsp;NGINX&amp;nbsp;deployments using dual docker container and Ingress NGINX on k8s are likewise not affected, as they do not run the affected NGINX versions.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Nevertheless, updated images including the latest supported NGINX components will be released shortly as part of Check Point's ongoing security and software maintenance process.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Customers independently managing external or customer-owned NGINX infrastructure running version 1.31.0 or 1.31.1 with HTTP/3 enabled are encouraged to review the vendor advisory and upgrade to NGINX 1.31.2, or disable HTTP/3 as an interim mitigation.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Check Point continuously monitors emerging vulnerabilities and security advisories as part of its ongoing product security and hardening processes.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 26 Jun 2026 08:32:53 GMT</pubDate>
    <dc:creator>Vani</dc:creator>
    <dc:date>2026-06-26T08:32:53Z</dc:date>
    <item>
      <title>NGINX CVE-2026-42530: Check Point-Managed and Self-Managed NGINX Deployments Not Affected</title>
      <link>https://community.checkpoint.com/t5/WAF/NGINX-CVE-2026-42530-Check-Point-Managed-and-Self-Managed-NGINX/m-p/278992#M414</link>
      <description>&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Description&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;A recently disclosed vulnerability, CVE-2026-42530 (&lt;/SPAN&gt;&lt;A href="https://www.cve.org/CVERecord?id=CVE-2026-42530" target="_blank"&gt;&lt;SPAN data-contrast="none"&gt;https://www.cve.org/CVERecord?id=CVE-2026-42530&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;), affects the NGINX ngx_http_v3_module used for HTTP/3.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;According to public reporting, this use-after-free condition can be triggered when NGINX uses the HTTP/3 QUIC module and a remote, unauthenticated attacker sends a crafted HTTP/3 session to reopen a QPACK encoder stream, corrupting memory in the worker process. The result is worker restarts and denial-of-service and, where ASLR is disabled or can be bypassed, possible code execution. The issue affects NGINX Open Source 1.31.0 and 1.31.1 only and was patched in 1.31.2. HTTP/3 must be explicitly enabled and is not on by default. Vendor advisory: K000161616 (&lt;/SPAN&gt;&lt;A href="https://my.f5.com/manage/s/article/K000161616" target="_blank"&gt;&lt;SPAN data-contrast="none"&gt;https://my.f5.com/manage/s/article/K000161616&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;).&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Check Point Statement Regarding NGINX Vulnerability CVE-2026-42530&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Following internal assessment and validation, Check Point confirms that Check Point WAF is not affected by CVE-2026-42530.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;The vulnerability is limited to NGINX Open Source versions 1.31.0 and 1.31.1. Check Point WAF does not run an NGINX version within this affected range, so the vulnerable code path is not present.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;All Check Point-managed NGINX deployments, including Check Point WAF SaaS, AppSec Gateway, and Single (Unified) Container, are not vulnerable to this issue.&amp;nbsp;Check Point WAF deployments&amp;nbsp;with&amp;nbsp;self-managed&amp;nbsp;NGINX&amp;nbsp;deployments using dual docker container and Ingress NGINX on k8s are likewise not affected, as they do not run the affected NGINX versions.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Nevertheless, updated images including the latest supported NGINX components will be released shortly as part of Check Point's ongoing security and software maintenance process.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Customers independently managing external or customer-owned NGINX infrastructure running version 1.31.0 or 1.31.1 with HTTP/3 enabled are encouraged to review the vendor advisory and upgrade to NGINX 1.31.2, or disable HTTP/3 as an interim mitigation.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Check Point continuously monitors emerging vulnerabilities and security advisories as part of its ongoing product security and hardening processes.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jun 2026 08:32:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/WAF/NGINX-CVE-2026-42530-Check-Point-Managed-and-Self-Managed-NGINX/m-p/278992#M414</guid>
      <dc:creator>Vani</dc:creator>
      <dc:date>2026-06-26T08:32:53Z</dc:date>
    </item>
  </channel>
</rss>

