Patches should be available, no excuses. https://depthfirst.com/research/nginx-rift-achieving-nginx-rce-via-an-18-year-old-vulnerability
CVSS 9.2 is no joke. DoS incoming.
Apache, Nginx and others: patch NOW!!! https://blog.calif.io/p/codex-discovered-a-hidden-http2-bomb
Again, if you're using NGINX, it's once more time to update update ASAP:
https://my.f5.com/manage/s/article/K000161614
CVSS 9.2 ranked issues are usually no joke!
Last updated: Aug 18 2026 at 08:27 UTC