Authentication Bypass by Spoofing in NGINX Open Source and NGINX Plus - CVE-2026-40460
Published: May 14, 2026
NGINX Open Source
NGINX Plus
Detailed vulnerability description
The vulnerability allows a remote attacker to bypass authorization or cause a denial of service.
The vulnerability exists due to authentication bypass by spoofing in the ngx_quic_module module when handling HTTP/3 QUIC traffic. A remote attacker can spoof their source IP address to bypass authorization or cause a denial of service.
There is no control plane exposure; this is a data plane issue only.