← Back

CVE-2026-1642

nvd nist
Published: Feb 4, 2026Modified: Jun 17, 2026

JSON object

Loading...
8.2
Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Show more
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: f5sirt@f5.com (Secondary)

Description

A vulnerability exists in NGINX OSS and NGINX Plus when configured to proxy to upstream Transport Layer Security (TLS) servers. An attacker with a man-in-the-middle (MITM) position on the upstream server side—along with conditions beyond the attacker's control—may be able to inject plain text data into the response from an upstream proxied server.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected (21)

5 products
Nginx Gateway Fabric
Nginx Ingress Controller
Nginx Instance Manager
Nginx Open Source
Nginx Plus
Configuration A
21 vulnerable
Vulnerable SoftwareAffected Versions
F5
From 1.2.0 to 1.6.2
From 2.0.0 to 2.4.1
F5
From 3.4.0 to 3.7.2
From 4.0.0 to 4.0.1
From 5.0.0 to 5.3.3
From 2.15.1 to 2.21.0
F5
From 1.29.0 to 1.29.5
From 1.3.0 to 1.28.2
F5
From r33 to r35
Version r32
Version r32 p1
Version r32 p2
Version r32 p3
Version r33 p1
Version r33 p2
Version r33 p3
Version r34 p1
Version r34 p2
Version r35
Version r36
Version r36 p1

References (2)

Source: f5sirt@f5.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory

Timeline

No history available yet.