Description
A recently disclosed vulnerability, CVE-2026-42530 (https://www.cve.org/CVERecord?id=CVE-2026-42530), affects the NGINX ngx_http_v3_module used for HTTP/3.
According to public reporting, this use-after-free condition can be triggered when NGINX uses the HTTP/3 QUIC module and a remote, unauthenticated attacker sends a crafted HTTP/3 session to reopen a QPACK encoder stream, corrupting memory in the worker process. The result is worker restarts and denial-of-service and, where ASLR is disabled or can be bypassed, possible code execution. The issue affects NGINX Open Source 1.31.0 and 1.31.1 only and was patched in 1.31.2. HTTP/3 must be explicitly enabled and is not on by default. Vendor advisory: K000161616 (https://my.f5.com/manage/s/article/K000161616).
Check Point Statement Regarding NGINX Vulnerability CVE-2026-42530
Following internal assessment and validation, Check Point confirms that Check Point WAF is not affected by CVE-2026-42530.
The vulnerability is limited to NGINX Open Source versions 1.31.0 and 1.31.1. Check Point WAF does not run an NGINX version within this affected range, so the vulnerable code path is not present.
All Check Point-managed NGINX deployments, including Check Point WAF SaaS, AppSec Gateway, and Single (Unified) Container, are not vulnerable to this issue. Check Point WAF deployments with self-managed NGINX deployments using dual docker container and Ingress NGINX on k8s are likewise not affected, as they do not run the affected NGINX versions.
Nevertheless, updated images including the latest supported NGINX components will be released shortly as part of Check Point's ongoing security and software maintenance process.
Customers independently managing external or customer-owned NGINX infrastructure running version 1.31.0 or 1.31.1 with HTTP/3 enabled are encouraged to review the vendor advisory and upgrade to NGINX 1.31.2, or disable HTTP/3 as an interim mitigation.
Check Point continuously monitors emerging vulnerabilities and security advisories as part of its ongoing product security and hardening processes.