Use-after-free in the QPACK encoder of nginx HTTP/3 Trang chủ Nghiên cứu Use-after-free in the QPA... Use-after-free in the QPACK encoder of nginx HTTP/3 19/06/2026 Trung Nguyen Hacker. Builder. Educator. On a mission to make the internet safer. 0 lượt xem 0 lượt xem Về tác giả Trung Nguyen Hacker. Builder. Educator. On a mission to make the internet safer. Hacker. Builder. Educator. On a mission to make the internet safer. Cập nhật thông tin mới nhất Nhận các thông tin mới nhất về mối đe dọa, báo cáo an ninh mạng từ CyStack về hòm thư điện tử của bạn Bài viết liên quan "<!DOCTYPE html>\n<html>\n <head>\n <title>Sign in ・ Cloudflare Access</title>\n \n <meta charset=\"utf-8\" />\n <meta name=\"robots\" content=\"noindex\" />\n <meta name=\"viewport\" content=\"initial-scale=1, maximum-scale=1, user-scalable=no, width=device-width\" />\n <link rel=\"icon\" type=\"image/svg+xml\" href=\"data:image/svg+xml,%3Csvg xmlns='http://www.w3.org/2000/svg' viewBox='0 0 62 50'%3E %3Cstyle%3E path %7B fill: url(%23gradient-light); %7D @media (prefers-color-scheme: dark) %7B path %7B fill: url(%23gradient-dark); %7D %7D %3C/style%3E %3Cdefs%3E %3ClinearGradient id='gradient-light' x1='30.7' y1='0' x2='30.7' y2='49.8' gradientUnits='userSpaceOnUse'%3E %3Cstop stop-color='%23332CB3'/%3E %3Cstop offset='1' stop-color='%23456FDD'/%3E %3C/linearGradient%3E %3ClinearGradient id='gradient-dark' x1='30.7' y1='0' x2='30.7' y2='49.8' gradientUnits='userSpaceOnUse'%3E %3Cstop stop-color='%23FFFFFF'/%3E %3Cstop offset='1' stop-color='%23E0E0E0'/%3E %3C/linearGradient%3E %3C/defs%3E %3Cpath d='M21.3 15.6h-7.8C17.2 6.4 26.1 0 36.6 0c13.7 0 24.9 11.1 24.9 24.9 0 13.7-11.1 24.9-24.9 24.9-10.4 0-19.4-6.4-23.1-15.6h7.8c3.1 5.1 8.8 8.6 15.3 8.6 9.9 0 17.9-8 17.9-17.9 0-9.9-8-17.9-17.9-17.9-6.5 0-12.1 3.4-15.3 8.6zm-12 14l-3.1-3.1h36.7c1.4 0 2.1 1.7 1.1 2.7l-6.2 6.2-2.2-2.2 3.6-3.6H9.3zm23-12.9l2.2-2.2 6.2 6.2c1 1 .3 2.7-1.1 2.7H3.1L0 20.2h35.9l-3.6-3.5z'/%3E %3C/svg%3E \" />\n <article id=\"data\"\n data-auto-redirect-to-identity=\"false\"\n data-auto-redirect-url=\"\"\n data-message=\"\">\n </article>\n <style>@charset \"UTF-8\";:root{color-scheme:light;--color-kumo-canvas:oklch(98.75% 0 0);--color-kumo-elevated:oklch(98% 0 0);--color-kumo-recessed:oklch(96% 0 0);--color-kumo-base:#fff;--color-kumo-tint:oklch(97% 0 0);--color-kumo-control:#fff;--color-kumo-line:oklch(14.5% 0 0 / 0.1);--color-kumo-hairline:oklch(93.5% 0 0);--color-kumo-fill:oklch(92.2% 0 0);--color-kumo-brand:oklch(57.72% 0.2324 260);--color-kumo-brand-hover:oklch(48.8% 0.243 264.376);--color-kumo-danger:oklch(63.7% 0.237 25.331);--color-kumo-focus:oklch(15% 0 0);--text-color-kumo-default:oklch(21% 0.006 285.885);--text-color-kumo-subtle:oklch(55.6% 0 0);--text-color-kumo-placeholder:oklch(70.8% 0 0);--text-color-kumo-link:oklch(42.4% 0.199 265.638);--text-color-kumo-info:oklch(42.4% 0.199 265.638);--text-color-kumo-warning:oklch(47.6% 0.114 61.907);--text-color-kumo-danger:oklch(50.5% 0.213 27.518);--text-color-kumo-success:oklch(43.2% 0.095 166.913);--radius-sm:4px;--radius-md:6px;--radius-lg:8px;--spacing:4px;--content-width:460px;--content-width-wide:540px;--page-bg-override:initial}*,::after,::before{-webkit-box-sizing:border-box;box-sizing:border-box}body,html{margin:0;padding:0;min-height:100vh;min-height:100dvh}html{text-rendering:optimizeLegibility;word-wrap:break-word}.Content,body{display:-webkit-box;display:-ms-flexbox;display:flex;-webkit-box-orient:vertical;-webkit-box-direction:normal;-ms-flex-direction:column;flex-direction:column}body{font-family:-apple-system,BlinkMacSystemFont,\"Segoe UI\",Helvetica,Arial,sans-serif;font-size:14px;line-height:20px;color:#4f566b;background:var(--page-bg-override, #003d7b);-webkit-font-smoothing:antialiased;-moz-osx-font-smoothing:grayscale;-webkit-box-align:center;-ms-flex-align:center;align-items:center;-webkit-box-pack:center;-ms-flex-pack:center;justify-content:center;padding:calc(var(--spacing)*8) calc(var(--spacing)*2);text-align:center}button{font-family:inherit}.Content{width:100%;max-width:var(--content-width);margin:0 auto;gap:calc(var(--spacing)*5)}.Content-is-wide{max-width:var(--content-width-wide)}.base_AccessLogo{display:-webkit-box;display:-ms-flexbox;display:flex;-webkit-box-pack:center;-ms-flex-pack:center;justify-content:center}.Content::after{content:\"\";display:block;height:41px;-ms-flex-negative:0;flex-shrink:0}.base_AccessLogo svg{width:280px;max-width:100%;height:auto;display:block}.AuthBox{width:100%;background:var(--color-kumo-base);border:1px solid var(--color-kumo-hairline);border-radius:var(--radius-lg);overflow:hidden;text-align:left}.AuthBox-body{padding:calc(var(--spacing)*8);display:-webkit-box;display:-ms-flexbox;display:flex;-webkit-box-orient:vertical;-webkit-box-direction:normal;-ms-flex-direction:column;flex-direction:column;gap:calc(var(--spacing)*4)}.AuthBox-body-is-centered,.OrgAvatarLink{-webkit-box-align:center;-ms-flex-align:center;align-items:center}.AuthBox-body-is-centered{text-align:center}.OrgAvatarLink{display:-webkit-box;display:-ms-flexbox;display:flex;gap:calc(var(--spacing)*3);text-decoration:none;color:inherit}.OrgAvatarLink-logo{-ms-flex-negative:0;flex-shrink:0;height:36px}.OrgAvatarLink-logo:has(img[src=\"\"]){display:none}.OrgAvatarLink-logo img{display:block;height:36px;width:auto;border-radius:var(--radius-sm)}.OrgAvatarLink-title{font-size:14px;line-height:20px;font-weight:500;color:var(--text-color-kumo-subtle)}.AuthBox-App{display:-webkit-box;display:-ms-flexbox;display:flex;-webkit-box-orient:vertical;-webkit-box-direction:normal;-ms-flex-direction:column;flex-direction:column;gap:var(--spacing)}.Card-title,.Header-text{color:var(--text-color-kumo-default)}.Card-title{margin:0;font-size:24px;line-height:32px;font-weight:600}.Header-text{background:var(--color-kumo-tint);border:1px solid var(--color-kumo-hairline);border-radius:var(--radius-md);padding:calc(var(--spacing)*3) calc(var(--spacing)*4);font-size:13px;line-height:18px}.AuthBox-App>.Header-text{margin-top:calc(var(--spacing)*3)}.AuthBox-text{line-height:20px;font-weight:500;margin:0 0 2px}.AuthBox-body p,.AuthBox-text,.StandardInput{font-size:14px;color:var(--text-color-kumo-default)}.AuthBox-body p{margin:0;line-height:20px}.StandardInput{-moz-appearance:none;appearance:none;-webkit-appearance:none;display:block;width:100%;height:44px;padding:0 calc(var(--spacing)*3);font:inherit;background:var(--color-kumo-control);border:1px solid var(--color-kumo-line);border-radius:var(--radius-lg);-webkit-transition:background-color 120ms ease;transition:background-color 120ms ease}.StandardInput::-webkit-input-placeholder{color:var(--text-color-kumo-placeholder)}.StandardInput::-moz-placeholder{color:var(--text-color-kumo-placeholder)}.StandardInput:-ms-input-placeholder{color:var(--text-color-kumo-placeholder)}.StandardInput::-ms-input-placeholder{color:var(--text-color-kumo-placeholder)}.StandardInput::placeholder{color:var(--text-color-kumo-placeholder)}.AuthFormLogin,.AuthFormLogin-row{display:-webkit-box;display:-ms-flexbox;display:flex;-webkit-box-orient:vertical;-webkit-box-direction:normal;-ms-flex-direction:column;flex-direction:column}.AuthFormLogin{gap:calc(var(--spacing)*3);margin:0}.AuthFormLogin-row{gap:var(--spacing)}.AuthFormLogin-row label,.Button{font-size:14px;line-height:20px;font-weight:500}.AuthFormLogin-row label{color:var(--text-color-kumo-default);margin-bottom:2px}.AuthFormLogin input[hidden]{display:none}.Button{-moz-appearance:none;appearance:none;-webkit-appearance:none;display:-webkit-inline-box;display:-ms-inline-flexbox;display:inline-flex;-webkit-box-align:center;-ms-flex-align:center;align-items:center;-webkit-box-pack:center;-ms-flex-pack:center;justify-content:center;gap:calc(var(--spacing)*2);height:44px;padding:0 calc(var(--spacing)*4);font-family:inherit;border-radius:var(--radius-lg);border:1px solid transparent;-webkit-box-shadow:0 1px 2px 0 rgba(0,0,0,.05);box-shadow:0 1px 2px 0 rgba(0,0,0,.05);cursor:pointer;text-decoration:none;white-space:nowrap;-webkit-user-select:none;-moz-user-select:none;-ms-user-select:none;user-select:none;-webkit-transition:background-color 120ms ease,border-color 120ms ease,color 120ms ease,-webkit-box-shadow 120ms ease,-webkit-transform 60ms ease;transition:background-color 120ms ease,border-color 120ms ease,color 120ms ease,box-shadow 120ms ease,transform 60ms ease;transition:background-color 120ms ease,border-color 120ms ease,color 120ms ease,box-shadow 120ms ease,transform 60ms ease,-webkit-box-shadow 120ms ease,-webkit-transform 60ms ease}.Button:focus-visible{outline-offset:2px}.Button:active{-webkit-transform:translateY(.5px);-ms-transform:translateY(.5px);transform:translateY(.5px)}.Button:disabled{opacity:.5;cursor:not-allowed;-webkit-transform:none;-ms-transform:none;transform:none}.Button-is-block{width:100%}.Button-is-juicy{background:var(--color-kumo-brand);color:#fff;border-color:var(--color-kumo-brand)}.Button-is-juicy:hover:not(:disabled){background:var(--color-kumo-brand-hover);border-color:var(--color-kumo-brand-hover)}.Button-is-auth{background:var(--color-kumo-base);color:var(--text-color-kumo-default);border-color:var(--color-kumo-hairline);-webkit-box-pack:start;-ms-flex-pack:start;justify-content:flex-start;padding:0 calc(var(--spacing)*4);gap:calc(var(--spacing)*3)}.Button-is-auth:hover:not(:disabled){background:var(--color-kumo-tint)}.Button-is-auth:active:not(:disabled){background:var(--color-kumo-fill)}.Button-auth-service-icon{-ms-flex-negative:0;flex-shrink:0;width:20px;height:20px;display:-webkit-inline-box;display:-ms-inline-flexbox;display:inline-flex;-webkit-box-align:center;-ms-flex-align:center;align-items:center;-webkit-box-pack:center;-ms-flex-pack:center;justify-content:center}.Button-auth-service-icon img,.Button-auth-service-icon svg{width:20px;height:20px;display:block}.AuthBoxRow--name{min-width:0;overflow:hidden;text-overflow:ellipsis;white-space:nowrap;font-size:14px;font-weight:500}.Footer-text{marg
A use-after-free vulnerability (CVE-2026-42530) exists in the QPACK encoder component of nginx's HTTP/3 implementation, which could allow an attacker to cause a denial of service or potentially execute arbitrary code. The article does not provide specific affected version ranges, a fixed version, or a CVSS score.