It was discovered that nginx did not properly validate source addresses in the HTTP/3 QUIC module. A remote attacker could possibly use this issue to bypass authorization checks or rate limiting. This issue only affected Ubuntu 25.04 and Ubuntu 25.10.
USN-8354-1: nginx vulnerabilities
calendar_today
June 1, 2026
domain
ubuntu