Executive brief
NGINX Plus and NGINX Open Source are widely used web server and reverse proxy solutions. A security flaw in the HTTP/3 QUIC module allows remote attackers to fake their source IP address. This could enable unauthorized users to bypass security restrictions, such as access controls or rate limits, potentially leading to unauthorized data access or service degradation.
Technical details
A vulnerability classified as 'Authentication Bypass by Spoofing' (CWE-290) exists in the ngx_quic_module of NGINX Plus and NGINX Open Source. When configured to use HTTP/3 QUIC, the software fails to properly validate or protect the source IP address, allowing a remote, unauthenticated attacker to spoof their identity. This spoofing can be leveraged to circumvent security policies that rely on IP-based authorization or rate limiting. The issue affects NGINX Open Source versions 1.25.0 through 1.30.0 and NGINX Plus versions R32 through R36. F5 has released updates (e.g., NGINX Open Source 1.30.1 and NGINX Plus R36 P4) to address this behavior.
Affected products
- F5 NGINX Plus R32 through R36 P3
- F5 NGINX Open Source 1.25.0 through 1.30.0
- F5 NGINX Ingress Controller 3.5.0-3.7.2, 4.0.0-4.0.1, 5.0.0-5.4.2
- F5 NGINX Gateway Fabric 1.3.0-1.6.2, 2.0.0-2.6.0
Timeline
- 2026-05-13: advisory
- 2026-05-13: disclosed