CVE-2026-42946Disclosure(f5 / dos)

LOWCVSS 7.4 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch f5 dos systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability exists in the ngx_http_scgi_module and ngx_http_uwsgi_module modules that may result in excessive memory allocation or an over-read of data. When scgi_pass or uwsgi_pass is configured, an unauthenticated attacker with man-in-the-middle (MITM) ability to control responses from an upstream server may be able to read the memory of the NGINX worker process or restart it.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

1.0/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-789CWE-823

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • dos
  • nginx_gateway_fabric
  • nginx_ingress_controller
  • nginx_instance_manager

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • Peaked 2d ago at 3 mentions (2026-05-15); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
dosnginx_gateway_fabricnginx_ingress_controllernginx_instance_managernginx_open_sourcenginx_pluswaf

1 version affected across 7 products

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-05-15: 3Mentions · 2026-05-16: 1Mentions · 2026-06-03: 1Patch / Workaround · 2026-05-15: 1Technical Details · 2026-05-15: 3Technical Details · 2026-05-16: 105-1505-1606-03
Signal classification3 categories
Disclosure
240.0%
General
240.0%
Patch
120.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-153
Disclosure1General1Patch1
2026-05-161
Disclosure1
2026-06-031
General1
Full discourse5 posts
  • Matthew Rosenquist@Matt_Rosenquist
    Disclosure

    More chained vulns are being discovered because of AI tools NGINX Rift is the latest Remote Code Execution (RCE), that combines 4 vulns CVE-2026-42945 Critical (9.2) CVE-2026-42946 High (8.3) CVE-2026-40701 Medium (6.3) CVE-2026-42934 Medium (6.3) https://api.cyfluencer.com/s/nginx-rift-chain-remote-code-execution-rce-discovered-leveraging-18-year-old-vulnerabilities-1cb958a3-27380/1

    Post summary

    The post announces the discovery of the NGINX Rift chained Remote Code Execution vulnerability affecting four CVEs, detailing their severity levels without offering exploit code or evidence of active attacks.

    00010123
    1.2K followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-42946: NGINX Memory Disclosure Bug - What It Means for Your Business and How to Respond https://hubs.li/Q04jVvkN0

    Post summary

    The provided text consists solely of a headline and a link, yielding no concrete evidence of exploitation, mitigation, or technical specifics.

    0000032
    32 followersView on X
  • Israel@f1tym1
    Disclosure

    CVE-2026-42946 | F5 NGINX Plus/NGINX Open Source ngx_http_scgi_module/ngx_http_uwsgi_module memory allocation (K000161027 / Nessus ID 314992) https://ift.tt/m7A29B5 A vulnerability classified as problematic has been found in F5 NGINX Plus and NGINX Open Source. Affected is an …

    Post summary

    The post announces a memory allocation flaw (CVE-2026-42946) in the SCGI and uWSGI modules of F5 NGINX Plus and NGINX Open Source, offering basic technical details but no PoC, exploit, or mitigation information.

    0000052
    974 followersView on X
  • Israel@f1tym1
    General

    CVE-2026-42946 | F5 NGINX Plus/NGINX Open Source ngx_http_scgi_module/ngx_http_uwsgi_module memory allocation (K000161027 / WID-SEC-2026-1527) https://ift.tt/m7A29B5 A vulnerability classified as problematic has been found in F5 NGINX Plus and NGINX Open Source. Affected is an…

    Post summary

    The snippet announces a memory allocation vulnerability (CVE‑2026‑42946) affecting F5 NGINX Plus and NGINX Open Source modules, but does not provide exploitation details, patches, or PoC information.

    0000054
    974 followersView on X
  • Vũ Trụ Số@vutruso
    Patch

    Nginx 1.31.0 Security Update - 6 CVEs Fixed CVE-2026-42945 - Heap buffer overflow in ngx_http_rewrite_module (potential code execution) CVE-2026-42926 - HTTP/2 request injection via proxy_set_body CVE-2026-42946 CVE-2026-42934 CVE-2026-40460 CVE-2026-40701 https://t.co/eRNItKkZIM

    Post summary

    The post announces a security update that fixes six CVEs, providing some technical details for two of them and confirming a patch has been released.

    0000085
    35 followersView on X
CPE platform detail8 entries

8 of 8 entries

PartVendorProductVersionTarget SWTarget HW
Appf5dos-nginx-
Appf5dos4.8.0nginx-
Appf5nginx_gateway_fabric---
Appf5nginx_ingress_controller---
Appf5nginx_instance_manager---
Appf5nginx_open_source---
Appf5nginx_plus---
Appf5waf-nginx-

Explore more