CVE-2026-32682

When NGINX Gateway Fabric is configured using GRPCRoutes, an authenticated, remote attacker with permission to create or modify GRPCRoute resources can cause the NGINX Gateway Fabric control plane to terminate by sending undisclosed GRPCRoute configurations containing backendRef filters. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
References
Link Resource
https://my.f5.com/manage/s/article/K000161786 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:f5:nginx_gateway_fabric:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_gateway_fabric:*:*:*:*:*:*:*:*

History

02 Jul 2026, 20:03

Type Values Removed Values Added
CPE cpe:2.3:a:f5:nginx_gateway_fabric:*:*:*:*:*:*:*:*
First Time F5 nginx Gateway Fabric
F5
References () https://my.f5.com/manage/s/article/K000161786 - () https://my.f5.com/manage/s/article/K000161786 - Vendor Advisory

18 Jun 2026, 14:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-17 20:16

Updated : 2026-07-02 20:03


NVD link : CVE-2026-32682

Mitre link : CVE-2026-32682

CVE.ORG link : CVE-2026-32682


JSON object : View

Products Affected

f5

  • nginx_gateway_fabric
CWE
CWE-129

Improper Validation of Array Index