• Latest
  • Trending
  • All
Answer card: the June 2026 nginx CVEs are critical but only affect HTTP/3 or HTTP/2-upstream/gRPC configs; a default static or HTTP/1.1 nginx is not exposed.

Is your nginx exposed? How to check and harden it

20 June 2026
Answer card stating that Ternary Bonsai 2 27B, released by PrismML on 17 September 2026 under Apache 2.0, packs Qwen3.8 27B into 5.95 gigabytes at 1.72 bits per weight, keeps 98.2 percent of the 14-benchmark average, about 75 percent on SWE-bench Verified and Terminal-Bench 2.1, and needs PrismML's llama.cpp fork to run.

Does Bonsai 2 27B really keep 98% of Qwen3.8 in 5.95 GB?

20 September 2026
Answer card stating that Jev 1.13 from TypeSafe AI is a decision model in early access since 15 September 2026 that returns typed probabilities instead of text, priced at 42 dollars per billion input tokens with output tokens free, answering in 70 to 500 milliseconds, with a 64K token request budget, text input only, and a documented list of things it does badly, including counting and dates.

Jev 1.13 bills $42 a billion tokens, and it can’t count

19 September 2026
Answer card stating that Qwen3.8-Omni-Flash launched on 17 September 2026 as an API only model on Alibaba Cloud Model Studio, taking text, images, audio and video in a 1M token context and returning text only, priced at 0.15 dollars per million input tokens for every modality and 0.47 dollars per million output tokens in the international regions, with no open weights published and the Qwen-Live Harness GitHub repository returning 404.

Qwen3.8-Omni-Flash bills audio at $0.15 and ships no weights

18 September 2026
Answer card stating that on 15 September 2026 AWS said it is unable to restore access to resources and data hosted exclusively in the Middle East Bahrain region me-south-1 and in the mec1-az2 zone of the UAE region, because the damage spanned multiple Availability Zones and exceeded what multi-AZ services are designed to withstand.

AWS can’t restore me-south-1, six months after the drone strikes

17 September 2026
Answer card stating that Google released Gemini 3.8 Live and Gemini 3.8 Live Extended Thinking on 15 September 2026 at 3 dollars per million audio input tokens and 12 dollars out, that the thinking model requires asynchronous tools, and that Artificial Analysis scores it 82.6 on its Speech to Speech Quality Index.

Gemini 3.8 Live Extended Thinking rejects any tool that blocks

16 September 2026
Answer card summarising the Atria Dawn Preview release: 744B GLM-5.2 base, MIT licence, 1.5 TB BF16 and 756 GB FP8 checkpoints, 256K context, top on five of sixteen benchmark rows and trailing on SWE-bench Pro.

Atria Dawn Preview is 744B under MIT, and the BF16 weighs 1.5 TB

15 September 2026
Answer card stating that OpenAI released the Agents API in public beta on 10 September 2026 with no separate fee, billed through model tokens, tool calls and hosted sandbox time, with a choice of OpenAI hosted, self hosted or partner sandboxes, US only data residency and no Zero Data Retention support.

OpenAI’s Agents API has no fee, no ZDR and a one hour sandbox clock

14 September 2026
Answer card: Sakana Fugu Max at $2 and $6 per million tokens, Fugu Ultra v2 unchanged at $5 and $30, and Sakana saying Ultra v2 scores without Fable 5 or GPT-6 Astra in its pool.

Fugu Max costs $2 and $6 while Fugu Ultra v2 runs without Fable 5

13 September 2026
Answer card stating that DeepSeek released DeepSeek-V4.1-Flash on 10 September 2026 as a 552 billion parameter mixture of experts model with a new causal encoder decoder architecture that activates 8 billion parameters on input and 16 billion on output, with native vision, a one million token context and MIT licensed weights, that the API model name is now deepseek-flash at 0.15 dollars per million input tokens and 0.60 dollars per million output tokens off peak, and that DeepSeek announced V4 Pro would be routed to V4.1-Flash from 14 September and reversed that on 11 September.

DeepSeek V4.1-Flash arrived, and the V4 Pro retirement lasted a day

12 September 2026
Answer card stating that Cognition released SWE-2 on 10 September 2026, a coding model post-trained from Kimi K3, scoring 50.0 percent on FrontierCode 1.1 Main against 50.9 percent for Claude Fable 5.1 and 27.3 percent on Terminal-Bench 4 against 55.8 percent, available only inside Devin.

SWE-2 trails Fable 5.1 by one point, and by 28 on Terminal-Bench 4

11 September 2026
Answer card for Meta Muse, free to 100 million tokens a week then $20 a month, launched 8 September 2026 for United States adults only, running in a dedicated per user virtual machine.

Does Meta Muse do enough to earn your inbox and a card on file?

9 September 2026
Answer card stating that the public download pages for the VMware Virtual Disk Development Kit on developer.broadcom.com began returning 404 errors on 25 August 2026 with no announcement or deprecation notice, that Broadcom support tells customers the kit is no longer available for use or download, and that release lines 7.0.3.1, 8.x and 9.x are all affected.

Broadcom pulled VDDK 8.0 and 9.0, and the 404 is the only notice

8 September 2026
  • About
  • Contact
  • Privacy
  • Legal
Sunday, September 20, 2026
  • Login
Packet Nebula
  • Home
  • Articles
    • Security
    • Network
    • Dev
    • Sysadmin
    • SEO
    • Email & DNS
  • Tools
    • Network tools: free, fast, no signup
    • Security tools: free, fast, no signup
    • Developer tools: free, fast, no signup
    • Sysadmin tools: free, fast, no signup
    • SEO tools: free, fast, no signup
    • Email & DNS tools: free, fast, no signup
  • Download
  • About
No Result
View All Result
Packet Nebula
No Result
View All Result
Home Security

Is your nginx exposed? How to check and harden it

by stephane
20 June 2026
in Security
0
Answer card: the June 2026 nginx CVEs are critical but only affect HTTP/3 or HTTP/2-upstream/gRPC configs; a default static or HTTP/1.1 nginx is not exposed.
495
SHARES
1.4k
VIEWS
Share on FacebookShare on Twitter

Two critical nginx holes, CVE-2026-42530 and CVE-2026-42055, both rated 9.2, dropped in June 2026, and the coverage made it sound like every nginx on earth was on fire. It wasn't. Each one only bites a specific setup. The first needs HTTP/3 switched on. The second needs you proxying to an upstream over HTTP/2, or running gRPC, with a couple of non-default buffers tweaked. A plain nginx serving files or reverse-proxying over HTTP/1.1 was never in range. So the honest first move isn't panic-patching, it's checking whether you even run the vulnerable config. Here's how to tell in about a minute, the version that actually fixes it, and the short hardening list that turns the next nginx CVE into a shrug.

The short answer

CVE-2026-42530 needs HTTP/3 enabled. CVE-2026-42055 needs HTTP/2 upstream proxying or gRPC with a couple of non-default options. If neither is you, these two can’t touch your nginx, though you should still move to 1.31.2 or 1.30.3 (NGINX Plus: R36 P6 or 37.0.2.1). Then harden, so the next one is a non-event.

9.2CVSS, both CVEs
2 configsactually at risk
1.31.2or 1.30.3: the fix
Answer card: the June 2026 nginx CVEs are critical but only affect HTTP/3 or HTTP/2-upstream and gRPC configs; a default nginx is not exposed.
Critical headline, narrow blast radius. The config is what decides if it's you.

Are you actually exposed?

Start here, because the answer is usually no. Both bugs are real and both work without authentication, but each one needs a config you had to switch on yourself.

CVE-2026-42530 is a use-after-free in the HTTP/3 module (ngx_http_v3_module). It only fires when you’ve actually turned HTTP/3 on, with something like listen 443 quic and http3 on in a server block. HTTP/3 is off by default, and plenty of builds don’t even ship the module, so if you never went looking for QUIC you’re almost certainly clear.

CVE-2026-42055 is a heap overflow in the HTTP/2 proxy and gRPC paths (ngx_http_proxy_v2_module, ngx_http_grpc_module). It needs proxy_http_version 2 or a grpc_pass, and on top of that ignore_invalid_headers off with large_client_header_buffers set above 2 MB. That’s a narrow corner. Most reverse proxies talk HTTP/1.1 to their upstreams and never touch those knobs.

So the static site. The WordPress box in front of php-fpm. The plain HTTP/1.1 reverse proxy. None of them were ever in range. Don’t take my word for it, check your own box:

Linux
nginx -v

That prints the version. Then sweep the config for the risky directives:

Linux
grep -REn "quic|http3|grpc_pass|proxy_http_version 2" /etc/nginx/

No matches, no exposure to these two. Matches, patch today and keep reading.

Terminal: nginx -v shows version 1.30.1, nginx -V shows http_v3_module is compiled in, and a grep of the config finds none of the risky directives enabled.
An honest check. The binary has HTTP/3 built in, but nothing turns it on, so this box is clear.

Patch to the fixed version

Exposed or not, upgrade. The releases that carry the fix:

  • NGINX Open Source: 1.31.2 on the mainline branch, or 1.30.3 on the 1.30 stable branch.
  • NGINX Plus: R36 P6, or 37.0.2.1 on the 37.0 line.

Check what you’re on with nginx -v. The catch is that your distro’s package often trails upstream by weeks, so a plain apt upgrade may not have the fix yet. The clean route is the official nginx.org repository, which tracks releases within days. Once the new binary is in, reload without dropping a single connection:

Linux
sudo nginx -t && sudo systemctl reload nginx

nginx -t tests the config first, so a stray typo can’t take the site down on reload. Small habit, saved me more than once.

Harden so the next one is a shrug

Patching is the reactive half. Hardening is the half where the next critical CVE lands and you barely look up, because the feature it abuses was never enabled and your version was never stale. The short list that earns its keep:

  • Watch the nginx security advisories and patch quickly. This is the one that genuinely matters. Everything below is depth.
  • Kill the version banner with server_tokens off;. It stops nginx printing its exact version in headers and error pages, which is the first line a scanner reads.
  • Enable only what you use. HTTP/3 is nice, but if you don’t need it, not building it in opts you straight out of a whole class of bug. Same logic for every module you’re tempted to add.
  • Lock down TLS and keep the cert chain clean. Our SSL checker shows the protocol and the full chain for any host in one look, and TLS 1.2 vs 1.3 covers what to actually switch on.
  • Send the security headers. HSTS, plus a content security policy that does more than default-src *. The HTTP headers checker grades what you’re serving and names the fix for each gap.
  • Rate-limit the obvious with limit_req and a sane client_max_body_size, so the cheap abuse never reaches your app.

None of that is exotic, and most of it is a few lines in a file you already have. The nginx that shrugs off the next headline is the boring one: patched, HTTP/3 off unless it’s earning its keep, a tidy header set, nothing switched on that nobody uses. If you run more than the one box, the same server-hardening basics sit underneath nginx itself, and they age just as well.

Frequently asked questions

Is my nginx affected by CVE-2026-42530 and CVE-2026-42055?

Only if you opted into the risky config. CVE-2026-42530 needs HTTP/3 enabled (listen ... quic, http3 on). CVE-2026-42055 needs HTTP/2 upstream proxying or gRPC, plus ignore_invalid_headers off and large_client_header_buffers above 2 MB. A default static or HTTP/1.1 reverse-proxy nginx is not affected, though you should still upgrade.

Which nginx version fixes the June 2026 CVEs?

NGINX Open Source 1.31.2 on the mainline branch, or 1.30.3 on the 1.30 stable branch. NGINX Plus users want R36 P6, or 37.0.2.1 on the 37.0 line. Check what you run with nginx -v.

How do I check which nginx version I am running?

Run nginx -v for the version, or nginx -V (capital) for the version plus the modules it was built with. Piping nginx -V into grep http_v3_module tells you whether HTTP/3 is even compiled in.

Do I need to disable HTTP/3 in nginx?

Only if you are not using it, and HTTP/3 is off by default, so most people have nothing to disable. If you did enable it and cannot patch right away, commenting out the quic listener and http3 on closes CVE-2026-42530 until you upgrade. If you rely on HTTP/3, just move to the fixed version.

What does CVSS 9.2 mean for these nginx bugs?

It is critical, and it reflects an unauthenticated remote attacker. The realistic worst case is a worker process crash, so a denial of service. Remote code execution is possible but needs ASLR disabled or bypassed, which raises the bar. The score assumes the vulnerable config is present; without it, your real exposure is close to nil.

Tags: cveguidehardeningnginxsecurityweb-server
Share198Tweet124
stephane

stephane

  • Trending
  • Comments
  • Latest
Answer card: Proton Lumo 2.0 is private by policy, not by locality. Saved history is locked so even Proton cannot read it, but the prompt is decrypted on a Proton EU server to answer it, then forgotten.

Proton Lumo 2.0 review: how private is it, really?

3 September 2026
The Agentic Coding section of the official Hy4 preview benchmark appendix published by Tencent, a table comparing Hy3 and Hy4 preview against DeepSeek V4 Pro 0813, Qwen 3.8 Max, GLM 5.3, Kimi K3, GPT 5.6 Sol and Claude Opus 5 across SWE-bench Multilingual, SWE-bench Pro, DeepSWE, three SWE Atlas tasks, SWE-Marathon, Terminal-Bench 2.1, NL2Repo-Bench, CyberGym, ProgramBench, PostTrainBench and Harbor-Index.

Tencent’s 770B Hy4 tops one benchmark row in 46

3 September 2026
Answer card: Qwen 3.7 Max is API-only and cannot run locally yet; the open Qwen models (Qwen 3.6 27B, qwen3:8b to 32b) run offline via Ollama.

Qwen 3.7 local: what you can actually run offline

22 June 2026
Answer card: JWTs are not encrypted, anyone can read them; the signature proves who issued the token, not who may read it.

Are JWTs encrypted? No, and the difference will bite you

0
Answer card: a random 8 character password falls in under 2 hours offline, while 16 random characters hold for 1.4 trillion years at the same speed.

How long does it take to crack a password in 2026?

0
Answer card: three DNS records decide if your mail lands or bounces; SPF lists allowed senders, DKIM signs messages, DMARC sets the failure policy.

SPF, DKIM and DMARC explained: the records your email needs

0
Answer card stating that Ternary Bonsai 2 27B, released by PrismML on 17 September 2026 under Apache 2.0, packs Qwen3.8 27B into 5.95 gigabytes at 1.72 bits per weight, keeps 98.2 percent of the 14-benchmark average, about 75 percent on SWE-bench Verified and Terminal-Bench 2.1, and needs PrismML's llama.cpp fork to run.

Does Bonsai 2 27B really keep 98% of Qwen3.8 in 5.95 GB?

20 September 2026
Answer card stating that Jev 1.13 from TypeSafe AI is a decision model in early access since 15 September 2026 that returns typed probabilities instead of text, priced at 42 dollars per billion input tokens with output tokens free, answering in 70 to 500 milliseconds, with a 64K token request budget, text input only, and a documented list of things it does badly, including counting and dates.

Jev 1.13 bills $42 a billion tokens, and it can’t count

19 September 2026
Answer card stating that Qwen3.8-Omni-Flash launched on 17 September 2026 as an API only model on Alibaba Cloud Model Studio, taking text, images, audio and video in a 1M token context and returning text only, priced at 0.15 dollars per million input tokens for every modality and 0.47 dollars per million output tokens in the international regions, with no open weights published and the Qwen-Live Harness GitHub repository returning 404.

Qwen3.8-Omni-Flash bills audio at $0.15 and ships no weights

18 September 2026
  • About
  • Contact
  • Privacy
  • Legal

Copyright © 2026 Stephane Cardon.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Articles
    • Security
    • Network
    • Dev
    • Sysadmin
    • SEO
    • Email & DNS
  • Tools
    • Network tools: free, fast, no signup
    • Security tools: free, fast, no signup
    • Developer tools: free, fast, no signup
    • Sysadmin tools: free, fast, no signup
    • SEO tools: free, fast, no signup
    • Email & DNS tools: free, fast, no signup
  • Download
  • About

Copyright © 2026 Stephane Cardon.