PT-2026-6052 · F5+5 · F5 Big-Ip+7

Jan Schaumann

·

Published

2026-01-01

·

Updated

2026-06-03

·

CVE-2026-1642

CVSS v4.0

8.2

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions NGINX OSS and NGINX Plus (affected versions not specified) F5 BIG-IP (affected versions not specified)
Description A flaw exists in NGINX OSS and NGINX Plus when used to proxy to upstream Transport Layer Security (TLS) servers. An attacker positioned in a man-in-the-middle (MITM) configuration on the upstream server side, alongside specific conditions outside of the attacker’s control, may be able to inject plain text data into the response from a proxied upstream server. F5 has identified vulnerabilities in BIG-IP, NGINX, and container services that create denial-of-service risks, particularly in high-traffic environments like web application firewalls and Kubernetes ingress. These vulnerabilities could allow attackers to overwhelm services remotely, causing disruptions to service availability. One specific vulnerability, CVE-2026-1642, allows for network-adjacent denial-of-service attacks through crafted requests.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Insufficient Verification of Data Authenticity

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:3638
ALSA-2026:4235
ALSA-2026:4705
ALSA-2026:5581
ALSA-2026:5599
AZL-76706
AZL-76745
BDU:2026-03559
BIT-NGINX-2026-1642
BIT-NGINX-GATEWAY-2026-1642
CVE-2026-1642
MGASA-2026-0033
OESA-2026-1572
OPENSUSE-SU-2026:10158-1
OPENSUSE-SU-2026:20784-1
RHSA-2026:3638
RHSA-2026:4235
RHSA-2026:4705
RHSA-2026:5581
RHSA-2026:5599
RHSA-2026:6182
RHSA-2026:6234
RHSA-2026:6235
RHSA-2026:6302
RHSA-2026:6311
RHSA-2026:6407
RHSA-2026:6408
RHSA-2026:6427
RHSA-2026:8346
SUSE-SU-2026:1761-1
SUSE-SU-2026:1953-1
SUSE-SU-2026:21823-1
USN-8038-1
USN-8375-1

Affected Products

F5 Big-Ip
Linuxmint
Nginx Oss
Nginx Plus
Nginx
Red Os
Rocky Linux
Ubuntu