CVE-2024-39792: F5 Nginx Plus

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

When the NGINX Plus is configured to use the MQTT pre-read module, undisclosed requests can cause an increase in memory resource utilization.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected products

  • F5 Nginx Plus: version r30 only; version r31 only; version r32 only

Published 2024-08-14. Last modified 2026-06-17.