CVE-2024-32760

NGINX HTTP/3 QUIC vulnerability

When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 encoder instructions can cause NGINX worker processes to terminate or cause or other potential impact.


We have discovered 141,906 live websites that are affected by CVE-2024-32760.

Run a Free Instant Scan




Affected Software

Product  Nginx
Category Web Servers
Vulnerable Domains141,906 live websites (4.57% of Nginx install base)
Vulnerable Versions
  • from 1.25 through 1.26.1
Vulnerable Versions Count8 versions ( 3.45% of all versions)


Common Weakness Enumeration

CWE-787 Out-of-bounds Write



Details

  • Published - May 29, 2024
  • Updated - Feb 13, 2025

Credits

  • F5 acknowledges Nils Bars of CISPA for bringing this issue to our attention and following the highest standards of coordinated disclosure. (reporter)

Website Distribution by Country

Number of websites using CVE-2024-32760
United States104,311 websites



India7,276 websites
Russia3,016 websites
Canada2,866 websites
Germany2,806 websites
China2,156 websites
GB2,131 websites
France1,925 websites
Australia1,223 websites
Italy1,089 websites

Website Distribution by TLD

Number of websites using CVE-2024-32760
.com91,419 websites
.org12,245 websites
.net5,087 websites
.ru2,820 websites
.ca2,008 websites
.co.uk1,544 websites
.com.au1,378 websites
.de1,307 websites
.it1,300 websites
.co574 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-32760

Top websites that are affected by CVE-2024-32760. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**.*****.com United States***
****.*******.org United States*,***
*****.com United States*,***
******.*****.com United States*,***
********.com United States*,***
***********.com Italy*,***
*********.ch United States*,***
******.ru Russia*,***
***********.com United States*,***
********.de Germany*,***
See full domain list

FAQ

CVE-2024-32760 is Out-of-bounds Write in Nginx
A total of 141,906 websites have been identified as vulnerable to CVE-2024-32760, based on global website indexing conducted by WebTechSurvey.
The Nginx is affected by the CVE-2024-32760 vulnerability.
Nginx versions up to 1.26.1 are vulnerable to CVE-2024-32760.
CVE-2024-32760 is resolved in version 1.26.1 of Nginx.