CVE-2026-32682(f5 / nginx_gateway_fabric)

LOWCVSS 7.1 · HIGH

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

When NGINX Gateway Fabric is configured using GRPCRoutes, an authenticated, remote attacker with permission to create or modify GRPCRoute resources can cause the NGINX Gateway Fabric control plane to terminate by sending undisclosed GRPCRoute configurations containing backendRef filters. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

0.0/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-129

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • nginx_gateway_fabric

Affected systems

Vendors
Products
nginx_gateway_fabric

Deep dive

Full discourse2 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-32682 Denial of Service in NGINX Gateway Fabric GRPCRoute Configuration https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-32682 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    A brief disclosure of CVE‑2026‑32682, a DoS vulnerability in NGINX Gateway Fabric’s GRPCRoute configuration, with a reference link but no additional technical or exploit details.

    0000051
    4.1K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-32682 When NGINX Gateway Fabric is configured using GRPCRoutes, an authenticated, remote attacker with permission to create or modify GRPCRoute resources can cause the NGIN… https://www.cve.org/CVERecord?id=CVE-2026-32682

    Post summary

    The tweet announces CVE-2026-32682, noting that authenticated attackers with permission to modify GRPCRoute resources can exploit NGINX Gateway Fabric, but no PoC, exploit code, patch, or evidence of active exploitation is provided.

    00000123
    57.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appf5nginx_gateway_fabric---

Explore more