When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 requests can cause NGINX worker processes to terminate or causeĀ other potential impact. This attack requires that a request be specifically timed during the connection draining process, which the attacker has no visibility and limited influence over.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: f5

Published: 2024-05-29T16:02:04.620Z

Updated: 2024-08-02T01:46:04.427Z

Reserved: 2024-05-14T16:31:57.492Z

Link: CVE-2024-31079

cve-icon Vulnrichment

Updated: 2024-08-02T01:46:04.427Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-05-29T16:15:09.800

Modified: 2024-06-10T18:15:31.023

Link: CVE-2024-31079

cve-icon Redhat

Severity : Moderate

Publid Date: 2024-05-29T00:00:00Z

Links: CVE-2024-31079 - Bugzilla