/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CVE-2024-31079

Published

Last updated

NVD

https://nvd.nist.gov/vuln/detail/CVE-2024-31079

Severity

4.8

Medium

CVSS V3

Description

When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 requests can cause NGINX worker processes to terminate or cause other potential impact. This attack requires that a request be specifically timed during the connection draining process, which the attacker has no visibility and limited influence over.

References

Affected packages


The trusted source for open source

Talk to an expert
© 2025 Chainguard. All Rights Reserved.
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing