Nginx · Nginx Oss · CVE-2026-1642
**Name of the Vulnerable Software and Affected Versions**
NGINX OSS and NGINX Plus (affected versions not specified)
F5 BIG-IP (affected versions not specified)
**Description**
A flaw exists in NGINX OSS and NGINX Plus when used to proxy to upstream Transport Layer Security (TLS) servers. An attacker positioned in a man-in-the-middle (MITM) configuration on the upstream server side, alongside specific conditions outside of the attacker’s control, may be able to inject plain text data into the response from a proxied upstream server. F5 has identified vulnerabilities in BIG-IP, NGINX, and container services that create denial-of-service risks, particularly in high-traffic environments like web application firewalls and Kubernetes ingress. These vulnerabilities could allow attackers to overwhelm services remotely, causing disruptions to service availability. One specific vulnerability, CVE-2026-1642, allows for network-adjacent denial-of-service attacks through crafted requests.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.