Security 2026-06-30 5분 NGINX HTTP/3·HTTP/2 동시 패치: CVE-2026-42530·42055 분석 NGINX 1.31.2가 막은 CVE-2026-42530·42055는 둘 다 CVSS 9.2 Critical이지만, RCE는 ASLR 우회 조건에서만 성립하고 실제 악용 정황은 아직 없다. HTTP/3 또는 HTTP/2 프록시를 쓰는 노출 서버라면 우선 패치 대상이다. #cve-2026-42055#cve-2026-42530#f5#heap-overflow#http2#http3#nginx#quic#rce#security#use-after-free#vulnerability