CVE-2026-11311(f5 / nginx_gateway_fabric)

LOWCVSS 6.5 · MEDIUM

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

When NGINX Plus is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in the NGINX configuration generator component of NGINX Gateway Fabric. User-supplied string values from the NginxProxy Custom Resource Definition serverTokens field and the AuthenticationFilter Custom Resource Definition extraAuthArgs field are rendered directly into NGINX configuration templates without sanitization or escaping. An authenticated attacker with permission to create or modify these Custom Resource Definitions may craft values that inject arbitrary NGINX configuration directives. This is a control plane issue; there is no data plane exposure from the vulnerability trigger itself. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

0.0/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-76CWE-74

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • nginx_gateway_fabric

Affected systems

Vendors
Products
nginx_gateway_fabric

Deep dive

Full discourse4 posts
  • Autumn Good@autumn_good_35
    Disclosure

    NGINXなどF5製品群で複数の脆弱性。 High CVEsは以下4件 CVE-2026-42530 CVE-2026-42055 CVE-2026-11311 CVE-2026-50107 K000161614: Out-of-band Security Notification (June 17, 2026) https://my.f5.com/manage/s/article/K000161614

    Post summary

    The post lists four high‑severity CVEs affecting F5 products and points to a vendor advisory, but provides no proof of concept, exploit details, or mitigation guidance.

    01010506
    6.9K followersView on X
  • CERT-PY@CERTpy
    Disclosure

    ⚠️ Vulnerabilidades en productos Nginx ❗ CVE-2026-42530 ❗ CVE-2026-42055 ❗ CVE-2026-11311 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-nginx-2/ https://t.co/ne7JkzO8KV

    Post summary

    The tweet announces three Nginx-related CVEs and points to external links for more information.

    00000171
    6.7K followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: #F5 released updates for vulns in #NGINX Open Source & #NGINX Gateway Fabric, incl CVE-2026-42530, CVE-2026-42055, CVE-2026-11311, and CVE-2026-50107. Exploitation could lead to DoS, arbitrary code execution, or NGINX configuration injection. #Patch #Patch #Patch.

    Post summary

    The post announces that F5 has released patches for several NGINX CVEs and highlights the potential exploit impacts.

    00000224
    7.2K followersView on X
  • m4rio@m4rio_eth
    Patch

    F5 patched criticals in nginx. GM The company also rolled out fixes for CVE-2026-11311 and CVE-2026-50107, two high-severity vulnerabilities in NGINX Gateway Fabric that could allow authenticated attackers to inject arbitrary NGINX configuration directives. please patch https://github.com/nginx/nginx-gateway-fabric and https://github.com/nginx/nginx

    Post summary

    F5 has released patches for two high‑severity NGINX Gateway Fabric CVEs (CVE‑2026‑11311 and CVE‑2026‑50107) that could allow authenticated attackers to inject arbitrary configuration directives; the announcement includes links to the patch repositories.

    00000301
    4.1K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appf5nginx_gateway_fabric---

Explore more