6.5
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
Description
When NGINX Plus or NGINX Open Source are configured to use the HTTP/3 QUIC module, an attacker may be able to spoof their source IP address allowing for bypass of authorization or bypass of rate limiting. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Basic Information
ID
CVE-2026-40460
Source
f5
Published
May 13, 2026 at 14:12
Affected Product
Vendor
F5
Product
NGINX Plus
Version
R37
Affected Versions
F5 NGINX Plus R36
F5 NGINX Plus R32
F5 NGINX Open Source 1.26.0
F5 NGINX Plus R32
F5 NGINX Open Source 1.26.0