PT-2026-50533 · F5 · Nginx Gateway Fabric

Published

2026-06-17

·

Updated

2026-06-17

·

CVE-2026-32682

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions NGINX Gateway Fabric (affected versions not specified)
Description When configured using GRPCRoutes, an authenticated remote attacker with permissions to create or modify GRPCRoute resources can cause the control plane to terminate. This occurs by sending specific GRPCRoute configurations that include backendRef filters.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Validation of Array Index

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-32682

Affected Products

Nginx Gateway Fabric