CVE-2026-1642Patch(f5 / nginx_gateway_fabric)

LOWCVSS 8.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch f5 nginx_gateway_fabric systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability exists in NGINX OSS and NGINX Plus when configured to proxy to upstream Transport Layer Security (TLS) servers. An attacker with a man-in-the-middle (MITM) position on the upstream server side—along with conditions beyond the attacker's control—may be able to inject plain text data into the response from an upstream proxied server.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

1.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-349CWE-345

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • nginx_gateway_fabric
  • nginx_ingress_controller
  • nginx_instance_manager
  • nginx_open_source

Threat summary

  • Patch or workaround signal is available
  • 23 mentions across 9 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 16 signals
  • Technical details provided in 8 signals
  • General: 5 classified signals
  • Disclosure: 1 classified signal
  • Peaked 7d ago at 6 mentions (2026-02-06); latest day: 1
  • 23 total mentions across 9 days

Affected systems

Vendors
Products
nginx_gateway_fabricnginx_ingress_controllernginx_instance_managernginx_open_sourcenginx_plus

5 versions affected across 5 products

Deep dive

Activity timeline23 mentions / 9d
02356Mentions · 2026-02-04: 1Mentions · 2026-02-06: 6Mentions · 2026-02-08: 1Mentions · 2026-02-09: 1Mentions · 2026-02-10: 4Mentions · 2026-02-12: 4Mentions · 2026-02-15: 4Mentions · 2026-02-19: 1Mentions · 2026-05-09: 1Patch / Workaround · 2026-02-06: 4Patch / Workaround · 2026-02-10: 4Patch / Workaround · 2026-02-12: 4Patch / Workaround · 2026-02-15: 2Patch / Workaround · 2026-02-19: 1Patch / Workaround · 2026-05-09: 1Technical Details · 2026-02-06: 3Technical Details · 2026-02-08: 1Technical Details · 2026-02-15: 3Technical Details · 2026-05-09: 102-0402-0602-0802-0902-1002-1202-1502-1905-09
Signal classification3 categories
Patch
1773.9%
General
521.7%
Disclosure
14.3%
Referenced assets18 URLs
Classification over time
DateTotalLabels
2026-02-041
General1
2026-02-066
General2Patch4
2026-02-081
Disclosure1
2026-02-091
General1
2026-02-104
Patch4
2026-02-124
Patch4
2026-02-154
General1Patch3
2026-02-191
Patch1
2026-05-091
Patch1
Full discourse20 posts
  • 현빈 | Hyunbin@hyunbinseo97
    Patch

    nginx 뒤에 HTTPS 서버 붙여놨으면 보안 취약점 있습니다. 업데이트하세요: > A vulnerability exists in NGINX OSS and NGINX Plus when configured to proxy to upstream Transport Layer Security (TLS) servers. https://www.cve.org/CVERecord?id=CVE-2026-1642

    Post summary

    CVE-2026-1642 is a vulnerability in NGINX OSS and Plus when proxying to upstream TLS servers, and the advisory recommends updating the software.

    061275528.5K
    3.4K followersView on X
  • Frank@jedisct1
    General

    NGINX vulnerability CVE-2026-1642 https://my.f5.com/manage/s/article/K000159824

    Post summary

    The post merely notes the existence of NGINX vulnerability CVE‑2026‑1642 and provides a link to an external article without specifying any technical or exploit details.

    2180805112.9K
    16.2K followersView on X
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2026-1642: NGINX < 1.29.5, 1.28.2 MitM injection https://www.openwall.com/lists/oss-security/2026/02/05/1 when configured to proxy to upstream TLS servers. MITM attacker on the upstream server side may be able to inject plaintext data into the response from an upstream proxied server.

    Post summary

    A MitM injection flaw is disclosed in NGINX versions below 1.29.5 and 1.28.2, allowing an attacker on an upstream TLS server to inject plaintext into proxied responses.

    030711.0K
    4.4K followersView on X
  • cPanel@cPanel
    Patch

    EasyApache 4 v25.46 is out: ✨ OWASP CRS 3.3.8 (fixes CVE-2026-21876) ✨ NGINX 1.29.5 (fixes CVE-2026-1642) ✨ NGINX modules rebuilt for 1.29.5 compatibility Changelog: #EasyApache #cPanelUpdates https://t.co/NBOvWyarOH

    Post summary

    The tweet announces an EasyApache 4 release that includes patches fixing CVE-2026-21876 and CVE-2026-1642, with no mention of PoC, active exploitation, or technical vulnerability details.

    10010293
    28.7K followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-nginx129 モジュール更新情報 1.29.5-1 KUSANAGI 9 を構成している各モジュールのアップデートを行いました。 アップデートにより適用される各モジュールのバージョンは、以下のとおりとなります。 nginx129 1.29.5-1 この更新には脆弱性(CVE-2026-1642)への対応が含まれます。 モジュールのアップデートについては、以下のコマンドで適用可能です。 # dnf upgrade nginxを使用している場合は以下のコマンドで再起動... https://kusanagi.tokyo/releases/23042/

    Post summary

    The Kusanagi‑Nginx module 1.29.5‑1 update includes a fix for CVE‑2026‑1642 and can be applied via dnf upgrade.

    0101081
    196 followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-nginx129 モジュール更新情報 1.29.5-1.el9 KUSANAGI 9 を構成している各モジュールのアップデートを行いました。 アップデートにより適用される各モジュールのバージョンは、以下のとおりとなります。 nginx129 1.29.5-1.el9 この更新には脆弱性(CVE-2026-1642)への対応が含まれます。 モジュールのアップデートについては、以下のコマンドで適用可能です。 # dnf upgrade nginxを使用している場合は以下の... https://kusanagi.tokyo/releases/23036/

    Post summary

    The Kusanagi Nginx module update 1.29.5-1.el9 includes a patch for CVE-2026-1642 and can be applied with the dnf upgrade command.

    0101079
    196 followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-nginx128 モジュール更新情報 1.28.2-1 KUSANAGI 9 を構成している各モジュールのアップデートを行いました。 アップデートにより適用される各モジュールのバージョンは、以下のとおりとなります。 nginx128 1.28.2-1 この更新には脆弱性(CVE-2026-1642)への対応が含まれます。 モジュールのアップデートについては、以下のコマンドで適用可能です。 # dnf upgrade nginxを使用している場合は以下のコマンドで再起動... https://kusanagi.tokyo/releases/23023/

    Post summary

    The kusanagi‑nginx128 module update (v1.28.2-1) incorporates a patch for CVE‑2026‑1642; no PoC, exploit code, or evidence of active exploitation is described.

    0101091
    196 followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-nginx128 モジュール更新情報 1.28.2-1.el9 KUSANAGI 9 を構成している各モジュールのアップデートを行いました。 アップデートにより適用される各モジュールのバージョンは、以下のとおりとなります。 nginx128 1.28.2-1.el9 この更新には脆弱性(CVE-2026-1642)への対応が含まれます。 モジュールのアップデートについては、以下のコマンドで適用可能です。 # dnf upgrade nginxを使用している場合は以下の... https://kusanagi.tokyo/releases/23014/

    Post summary

    The kusanagi-nginx128 update 1.28.2-1.el9 includes a patch for CVE-2026-1642, with no PoC, exploit, or active exploitation details mentioned.

    0101088
    196 followersView on X
  • ADINATA@_4dinata
    General

    Nginx Vuln CVE-2026-1642 https://t.co/WRdHjFOuhn

    Post summary

    The tweet references the Nginx vulnerability CVE-2026-1642 but does not provide additional information or context.

    1000099
    513 followersView on X
  • ThreatCluster@threatcluster
    Patch

    BREAKING: openSUSE Leap 15.6 releases nginx update fixing 4 critical flaws CVE-2026-1642, -27654, -27784, -28753 affecting multiple architectures, admins urged to patch now. https://threatcluster.io/cluster/critical-vulnerabilities-found-in-nginx-affecting-opensuse-l-b507ffe3

    Post summary

    The openSUSE Leap 15.6 update includes patches for four critical nginx CVEs, and administrators are urged to apply the fixes immediately.

    0000078
    221 followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    Heads up, #Fedora 42 sysadmins! A new advisory (FEDORA-2026-0b8cc86e5b) is out for nginx-mod-naxsi and the NGINX core. It addresses CVE-2026-1642, a data injection vulnerability in TLS proxied connections. Read more: 👉 https://tinyurl.com/58tvr3uj #Security https://t.co/9GLMZTpWPv

    Post summary

    A new Fedora advisory alerts sysadmins to a data injection flaw (CVE‑2026‑1642) affecting NGINX TLS proxied connections, emphasizing the need to address the issue with the forthcoming patch.

    0000065
    1.3K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    Urgent: #Fedora 42 ships nginx-mod-headers-more-0.39-6 to kill CVE-2026-1642. This critical MITM flaw lets attackers inject data via TLS proxied connections. Patch affects Nginx 1.28.2 core. Read more: 👉 https://tinyurl.com/59pjs9d3 #Security https://t.co/H3uknJFVOS

    Post summary

    Fedora 42 includes an update for CVE-2026-1642, a critical TLS MITM flaw allowing data injection in proxied connections, with the patch targeting Nginx 1.28.2 core.

    0000057
    1.3K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    #Fedora 42 admins: A critical Nginx update (CVE-2026-1642) is out. This patches a data injection vulnerability in TLS proxying. Read more: 👉 https://tinyurl.com/454fruu3 #Security https://t.co/0lTLessXej

    Post summary

    The tweet announces that a critical Nginx update has been released for Fedora 42, patching a data injection vulnerability in TLS proxying (CVE‑2026‑1642).

    0000060
    1.3K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    General

    A critical security advisory for #Fedora 42 administrators was published today regarding CVE-2026-1642. Read more: 👉 https://tinyurl.com/2wmp3f2c #Security https://t.co/AIGatWoqqB

    Post summary

    The tweet announces a critical advisory for Fedora 42 regarding CVE‑2026‑1642 but provides no further technical details or actionable information.

    0000050
    1.3K followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-nginx129 Module Update 1.29.5-1 KUSANAGI 9 modules have been updated. The updated modules are as follows: nginx129 1.29.5-1 This update includes support for vulnerability(CVE-2026-1642). The module update can be applied with the... https://kusanagi.tokyo/en/releases/23043/

    Post summary

    Kusanagi released module update 1.29.5-1 that patches CVE-2026-1642 via the nginx129 module.

    0000053
    196 followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-nginx129 Module Update 1.29.5-1.el9 KUSANAGI 9 modules have been updated. The updated modules are as follows: nginx129 1.29.5-1.el9 This update includes support for vulnerability(CVE-2026-1642). The module update can be applied with... https://kusanagi.tokyo/en/releases/23037/

    Post summary

    The kusanagi-nginx129 module has been updated to v1.29.5-1.el9, which includes a patch for CVE-2026-1642.

    0000048
    196 followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-nginx128 Module Update 1.28.2-1 KUSANAGI 9 modules have been updated. The updated modules are as follows: nginx128 1.28.2-1 This update includes support for vulnerability(CVE-2026-1642). The module update can be applied with the... https://kusanagi.tokyo/en/releases/23024/

    Post summary

    KUSANAGI released an update (1.28.2-1) that patches CVE-2026-1642, with no exploit or PoC details disclosed.

    0000053
    196 followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-nginx128 Module Update 1.28.2-1.el9 KUSANAGI 9 modules have been updated. The updated modules are as follows: nginx128 1.28.2-1.el9 This update includes support for vulnerability(CVE-2026-1642). The module update can be applied with... https://kusanagi.tokyo/en/releases/23015/

    Post summary

    The KUSANAGI 9 module update addresses CVE-2026-1642 by providing a patch; no proof of concept, exploit code, or active exploitation details are mentioned.

    0000054
    196 followersView on X
  • Mas73r@Mas73r
    General

    CVE Record: CVE-2026-1642 https://www.cve.org/CVERecord?id=CVE-2026-1642

    Post summary

    The text only provides a link to the CVE-2026-1642 record, with no additional details.

    0000051
    470 followersView on X
  • Davide Bellini@billmn
    Patch

    @runcloud hey guys, have you any plan to distribuite automatically a patch on servers for the NGINX CVE-2026-1642?

    Post summary

    The tweet is a question about a plan to automatically distribute a patch for NGINX CVE‑2026‑1642, focusing on patch management rather than exploitation details.

    0000068
    172 followersView on X
CPE platform detail17 entries

17 of 17 entries

PartVendorProductVersionTarget SWTarget HW
Appf5nginx_gateway_fabric---
Appf5nginx_ingress_controller---
Appf5nginx_instance_manager---
Appf5nginx_open_source---
Appf5nginx_plus---
Appf5nginx_plusr32--
Appf5nginx_plusr32--
Appf5nginx_plusr32--
Appf5nginx_plusr32--
Appf5nginx_plusr33--
Appf5nginx_plusr33--
Appf5nginx_plusr33--
Appf5nginx_plusr34--
Appf5nginx_plusr34--
Appf5nginx_plusr35--
Appf5nginx_plusr36--
Appf5nginx_plusr36--

Explore more