CVE-2026-42926General(f5 / nginx_gateway_fabric)

LOWCVSS 6.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch f5 nginx_gateway_fabric systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

When NGINX Open Source is configured to proxy HTTP/2 traffic by setting proxy_http_version to 2, and also uses proxy_set_body, an attacker may be able to inject frame headers and payload bytes to the upstream peer.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

1.0/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-172

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • nginx_gateway_fabric
  • nginx_ingress_controller
  • nginx_instance_manager
  • nginx_open_source

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • General: 3 classified signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-05-15); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
nginx_gateway_fabricnginx_ingress_controllernginx_instance_managernginx_open_source

Deep dive

Activity timeline5 mentions / 3d
01122Mentions · 2026-05-15: 2Mentions · 2026-05-16: 2Mentions · 2026-07-27: 1Patch / Workaround · 2026-05-15: 1Technical Details · 2026-05-15: 1Technical Details · 2026-05-16: 105-1505-1607-27
Signal classification3 categories
General
360.0%
Patch
120.0%
Disclosure
120.0%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-05-152
General1Patch1
2026-05-162
General2
2026-07-271
Disclosure1
Full discourse5 posts
  • mufeed vh@mufeedvh
    Disclosure

    Introducing ENDGINX - 5 CVEs in NGINX with open models. We let loose GLM 5.1 and 5.2 by @Zai_org on the NGINX codebase. The work resulted in six fixed vulnerabilities across five CVEs: CVE-2026-28755, CVE-2026-42926, CVE-2026-9256, CVE-2026-42055, and CVE-2026-42533. First of our open-model vulnerability research series. https://winfunc.com/research/endginx

    Post summary

    The post announces the discovery of five NGINX CVEs by the ENDGINX project using GLM 5.1/5.2, but no exploit details, patch information, or active exploitation are disclosed.

    130192549.2K
    4.8K followersView on X
  • mufeed vh@mufeedvh
    General

    We're doing an experiment with open models @winfunction to see how far we can push them to find vulns in hardened targets. So far: - $4.5K in bounties from Chrome VRP with a few more pending, with the scans costing less than $100. - 2 CVEs in NGINX (CVE-2026-28755 & CVE-2026-42926). And watch out for the next release! - And 60ca500faea0fc70816bb9c53af3815e2af3e6c962b4b4ea63c33c62ebb4240d 👀 We're writing a blog on this soon.

    Post summary

    The post notes two new NGINX CVEs but offers no technical detail, PoC, exploit code, mitigation, or evidence of active exploitation.

    51321014713.1K
    4.8K followersView on X
  • Israel@f1tym1
    General

    CVE-2026-42926 | F5 NGINX Open Source up to 1.30.0 encoding error (K000161131 / Nessus ID 314992) https://ift.tt/85FAKX9 A vulnerability described as problematic has been identified in F5 NGINX Open Source up to 1.30.0. This impacts an unknown function. Executing a manipulatio…

    Post summary

    The post announces a new encoding error vulnerability (CVE-2026-42926) affecting F5 NGINX Open Source up to 1.30.0 and includes a link for more details, but lacks information on exploitation, patching, or a PoC.

    0000047
    974 followersView on X
  • Israel@f1tym1
    General

    CVE-2026-42926 | F5 NGINX Open Source up to 1.30.0 encoding error (K000161131 / WID-SEC-2026-1527) https://ift.tt/85FAKX9 A vulnerability described as problematic has been identified in F5 NGINX Open Source up to 1.30.0. This impacts an unknown function. Executing a manipulati…

    Post summary

    The post announces a CVE for F5 NGINX Open Source but offers only minimal information, with no evidence of exploits, patches, or active use.

    0000047
    974 followersView on X
  • Vũ Trụ Số@vutruso
    Patch

    Nginx 1.31.0 Security Update - 6 CVEs Fixed CVE-2026-42945 - Heap buffer overflow in ngx_http_rewrite_module (potential code execution) CVE-2026-42926 - HTTP/2 request injection via proxy_set_body CVE-2026-42946 CVE-2026-42934 CVE-2026-40460 CVE-2026-40701 https://t.co/eRNItKkZIM

    Post summary

    The text announces a security update that patches six CVEs, providing minimal technical details for two and no evidence of exploitation or PoC.

    0000085
    35 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
Appf5nginx_gateway_fabric---
Appf5nginx_ingress_controller---
Appf5nginx_instance_manager---
Appf5nginx_open_source---

Explore more