Impact
The vulnerability is a limited heap buffer overflow that can happen during a TLS handshake in NGINX’s HTTP/3 module when OpenSSL versions 3.5.0 or earlier are used under certain configurations. The overflow is non‑deterministic, beyond an attacker’s direct control, yet it can cause a worker process restart or limited data corruption. The result is a denial of service manifested as a server crash or degraded request handling.
Affected Systems
This flaw affects both the NGINX Open Source and NGINX Plus distributions, as distributed by F5. The issue manifests when HTTP/3 is enabled through the listen directive in the configuration while using OpenSSL versions 3.5.0 or earlier; no specific product versions are enumerated in the advisory, implying that all editions with the vulnerable module are susceptible.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate to high severity, but the EPSS score is < 1% and the vulnerability is not listed in CISA KEV, indicating a very low probability of exploitation and no known zero‑day exploits. The likely attack vector is a network intrusion that triggers the TLS handshake over HTTP/3, which is typically reachable from the public facing interface of the load balancer. Due to the nondeterministic nature of the failure, the exploitability is lower than a deterministic buffer overflow, but the potential for denial of service remains significant.
OpenCVE Enrichment