CVE-2026-48142Patch(f5 / dos)

LOWCVSS 6.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch f5 dos systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When content is served or proxied through a location block with both source_charset utf-8; and a charset directive (for example, charset koi8-r;) configured, remote, unauthenticated attackers can send requests (in conjunction with conditions beyond their control) to cause a heap buffer over-read in the NGINX worker process, leading to limited disclosure of memory or a restart. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

1.0/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-125

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • dos
  • nginx_gateway_fabric
  • nginx_ingress_controller
  • nginx_instance_manager

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 1 signal
  • General: 2 classified signals
  • Peaked 2d ago at 2 mentions (2026-06-17); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
dosnginx_gateway_fabricnginx_ingress_controllernginx_instance_managernginx_open_sourcenginx_pluswaf

2 versions affected across 7 products

Deep dive

Activity timeline5 mentions / 3d
01122Mentions · 2026-06-17: 2Mentions · 2026-06-18: 2Mentions · 2026-06-25: 1Patch / Workaround · 2026-06-17: 1Patch / Workaround · 2026-06-18: 1Patch / Workaround · 2026-06-25: 1Technical Details · 2026-06-18: 106-1706-1806-25
Signal classification2 categories
Patch
360.0%
General
240.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-06-172
General1Patch1
2026-06-182
General1Patch1
2026-06-251
Patch1
CPE platform detail15 entries

15 of 15 entries

PartVendorProductVersionTarget SWTarget HW
Appf5dos-nginx-
Appf5dos4.9.0nginx-
Appf5nginx_gateway_fabric---
Appf5nginx_ingress_controller---
Appf5nginx_instance_manager---
Appf5nginx_open_source---
Appf5nginx_plus---
Appf5nginx_plus---
Appf5nginx_plusr36--
Appf5nginx_plusr36--
Appf5nginx_plusr36--
Appf5nginx_plusr36--
Appf5nginx_plusr36--
Appf5nginx_plusr36--
Appf5waf-nginx-

Explore more