CVE-2026-1642: F5 Nginx Gateway Fabric
Medium severity, CVSS 5.9. EPSS: 0.4% chance of exploitation in the next 30 days.
A vulnerability exists in NGINX OSS and NGINX Plus when configured to proxy to upstream Transport Layer Security (TLS) servers. An attacker with a man-in-the-middle (MITM) position on the upstream server side—along with conditions beyond the attacker's control—may be able to inject plain text data into the response from an upstream proxied server. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected products
- F5 Nginx Gateway Fabric: from 1.2.0, up to and including 1.6.2; from 2.0.0, before 2.4.1 (fixed in 2.4.1)
- F5 Nginx Ingress Controller: from 3.4.0, up to and including 3.7.2; from 4.0.0, up to and including 4.0.1; from 5.0.0, before 5.3.3 (fixed in 5.3.3)
- F5 Nginx Instance Manager: from 2.15.1, up to and including 2.21.0
- F5 Nginx Open Source: from 1.3.0, before 1.28.2 (fixed in 1.28.2); from 1.29.0, before 1.29.5 (fixed in 1.29.5)
- F5 Nginx Plus: from r33, before r35 (fixed in r35); version r32 only; version r33 only; version r34 only; version r35 only; version r36 only
Published 2026-02-04. Last modified 2026-06-17.