CVE-2026-40460Disclosure(f5 / dos)

LOWCVSS 6.9 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch f5 dos systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

When NGINX Plus or NGINX Open Source are configured to use the HTTP/3 QUIC module, an attacker may be able to spoof their source IP address allowing for bypass of authorization or bypass of rate limiting.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

1.0/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-290

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • dos
  • nginx_gateway_fabric
  • nginx_ingress_controller
  • nginx_instance_manager

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-05-15); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
dosnginx_gateway_fabricnginx_ingress_controllernginx_instance_managernginx_open_sourcenginx_pluswaf

1 version affected across 7 products

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-05-15: 2Mentions · 2026-05-16: 1Patch / Workaround · 2026-05-15: 1Technical Details · 2026-05-15: 2Technical Details · 2026-05-16: 105-1505-16
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-05-152
Disclosure1Patch1
2026-05-161
Disclosure1
Full discourse3 posts
  • Israel@f1tym1
    Disclosure

    CVE-2026-40460 | F5 NGINX Plus/NGINX Open Source Source IP Address authentication spoofing (K000161068 / Nessus ID 314992) https://ift.tt/Zv72Ky0 A vulnerability was found in F5 NGINX Plus and NGINX Open Source. It has been declared as critical. This affects an unknown functio…

    Post summary

    CVE-2026-40460 is a newly disclosed critical vulnerability in F5 NGINX Plus and NGINX Open Source that allows source IP address authentication spoofing. No patch, exploit, or active exploitation information is provided.

    0000047
    974 followersView on X
  • Israel@f1tym1
    Disclosure

    CVE-2026-40460 | F5 NGINX Plus/NGINX Open Source Source IP Address authentication spoofing (K000161068 / WID-SEC-2026-1527) https://ift.tt/Zv72Ky0 A vulnerability was found in F5 NGINX Plus and NGINX Open Source. It has been declared as critical. This affects an unknown functi…

    Post summary

    The post announces CVE‑2026‑40460, a source‑IP address authentication spoofing vulnerability affecting F5 NGINX Plus and NGINX Open Source, and notes that it has been classified as critical.

    0000055
    974 followersView on X
  • Vũ Trụ Số@vutruso
    Patch

    Nginx 1.31.0 Security Update - 6 CVEs Fixed CVE-2026-42945 - Heap buffer overflow in ngx_http_rewrite_module (potential code execution) CVE-2026-42926 - HTTP/2 request injection via proxy_set_body CVE-2026-42946 CVE-2026-42934 CVE-2026-40460 CVE-2026-40701 https://t.co/eRNItKkZIM

    Post summary

    The update announces Nginx 1.31.0 patching six CVEs, detailing two vulnerabilities while providing no PoC, exploit, or evidence of active exploitation.

    0000085
    35 followersView on X
CPE platform detail8 entries

8 of 8 entries

PartVendorProductVersionTarget SWTarget HW
Appf5dos-nginx-
Appf5dos4.8.0nginx-
Appf5nginx_gateway_fabric---
Appf5nginx_ingress_controller---
Appf5nginx_instance_manager---
Appf5nginx_open_source---
Appf5nginx_plus---
Appf5waf-nginx-

Explore more