рд╕реБрд░рдХреНрд╖рд╛ рд╕рд▓рд╛рд╣ рдкрд░ рд╡рд╛рдкрд╕ рдЬрд╛рдПрдБ

ЁЯЪи Nginx 1.31.2, 1.30.3 CVE

CVE-2026-42530 is a use-after-free in nginx that can occur when using HTTP/3 and processing a specially crafted QUIC session, fixed in nginx 1.31.2 and 1.30.3 (17 June 2026). Exploitation can corrupt worker process memory or crash the worker. DirectAdmin servers running nginx with HTTP/3 enabled should update through CustomBuild.

High 8.1 CVSS
DirectAdmin

рдкреНрд░рднрд╛рд╡рд┐рдд рд╕рдВрд╕реНрдХрд░рдг

1.31.2

рдбрд┐рдлрд╝реЙрд▓реНрдЯ рдЕрдкрдбреЗрдЯ рдХрдорд╛рдВрдб

cd /usr/local/directadmin/custombuild && ./build update_versions

SharedLicense рд▓рд╛рдЗрд╕реЗрдВрд╕ рдХреЗ рддрд╣рдд рдЗрд╕рдХрд╛ рдЕрд░реНрде

A crafted QUIC session can cause worker process memory corruption or segmentation faults, taking sites served by that worker offline.

Changes with nginx 1.31.2 17 Jun 2026

*) Security: use-after-free might occur when using HTTP/3 and processing

a specially crafted QUIC session, allowing an attacker to cause

worker process memory corruption or segmentation fault in a worker

process (CVE-2026-42530).

Thanks to Trung Nguyen of CyStack.

*) Security: a heap memory buffer overflow might occur in a worker

process when using a configuration with “ignore_invalid_headers off;”

and “large_client_header_buffers” with large configured values when

proxying a specially crafted request to HTTP/2 or gRPC backend,

allowing an attacker to cause worker process memory corruption or

segmentation fault in a worker process (CVE-2026-42055).

Thanks to Mufeed VH of Winfunc Research.

*) Security: a heap memory buffer overread might occur in a worker

process while handling a specially sent response with decoding from

UTF-8 via the “charset_map” directive, allowing an attacker to cause

a limited disclosure of worker proccess memory or segmentation fault

in a worker process (CVE-2026-48142).

Thanks to Han Yan of Xiaomi and p4p3r of CYBERONE.

*) Change: now the $request_id variable uses SipHash-2-4.

*) Feature: the $ssl_sigalgs variable.

*) Bugfix: a variable defined by the “split_clients” directive might be

empty if all percentages were specified explicitly and summed up to

100%.

*) Bugfix: constant time “secure_link” hash comparison.

Thanks to kodareef5.

рдЕрдХреНрд╕рд░ рдкреВрдЫреЗ рдЬрд╛рдиреЗ рд╡рд╛рд▓реЗ рдкреНрд░рд╢реНрди

What is CVE-2026-42530?
It is a use-after-free flaw (CWE-416, CVSS 8.1) in nginx's handling of HTTP/3 QUIC sessions. A specially crafted session can corrupt worker process memory or segfault the worker. Credit for the finding goes to Trung Nguyen of CyStack.
Which nginx versions fix CVE-2026-42530?
nginx 1.31.2 and the 1.30.3 stable backport, released 17 June 2026. The same release also fixed a heap buffer overflow in HTTP/2/gRPC proxying (CVE-2026-42055) and a heap overread, so updating covers several flaws at once.
Do I need HTTP/3 enabled to be exposed?
The CVE-2026-42530 use-after-free is in HTTP/3 QUIC session processing, so servers with HTTP/3 enabled are the ones exposed to it. Updating to 1.31.2 or 1.30.3 removes the concern either way.
How do I update nginx on a DirectAdmin server?
Run: cd /usr/local/directadmin/custombuild && ./build update_versions, then verify with nginx -v that the running build is 1.31.2 / 1.30.3 or later.

рд╕реБрд░рдХреНрд╖рд╛ рд╕рд▓рд╛рд╣

рд╕рдВрдмрдВрдзрд┐рдд рд╕рд▓рд╛рд╣

рдЕрдкрдиреЗ рд╕рд┐рд╕реНрдЯрдо рдореЗрдВ рднреЗрджреНрдпрддрд╛рдУрдВ рдХреА рдЬрд╛рдБрдЪ рдХрд░реЗрдВ

рдЕрдкрдирд╛ рдЙрддреНрдкрд╛рдж рдФрд░ рдСрдкрд░реЗрдЯрд┐рдВрдЧ рд╕рд┐рд╕реНрдЯрдо рдЪреБрдиреЗрдВ рддрд╛рдХрд┐ рдЖрдкрдХреЗ рд▓рд┐рдП рд▓рд╛рдЧреВ рд╕рдЯреАрдХ рдлрд┐рдХреНрд╕ рдХрдорд╛рдВрдб рджреЗрдЦ рд╕рдХреЗрдВред

рдЕрдкрдирд╛ рд╕рд┐рд╕реНрдЯрдо рдЬрд╛рдБрдЪреЗрдВ