CVE-2026-40460

When NGINX Plus or NGINX Open Source are configured to use the HTTP/3 QUIC module, an attacker may be able to spoof their source IP address allowing for bypass of authorization or bypass of rate limiting.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
References
Link Resource
https://my.f5.com/manage/s/article/K000161068 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:f5:dos:*:*:*:*:*:nginx:*:*
cpe:2.3:a:f5:dos:4.8.0:*:*:*:*:nginx:*:*
cpe:2.3:a:f5:nginx_gateway_fabric:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_gateway_fabric:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_ingress_controller:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_ingress_controller:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_ingress_controller:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_instance_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_open_source:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_plus:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:waf:*:*:*:*:*:nginx:*:*
cpe:2.3:a:f5:waf:*:*:*:*:*:nginx:*:*
cpe:2.3:a:f5:waf:*:*:*:*:*:nginx:*:*

History

29 Jun 2026, 14:17

Type Values Removed Values Added
CPE cpe:2.3:a:f5:waf:*:*:*:*:*:nginx:*:*
cpe:2.3:a:f5:nginx_open_source:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_ingress_controller:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_instance_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_plus:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:dos:4.8.0:*:*:*:*:nginx:*:*
cpe:2.3:a:f5:dos:*:*:*:*:*:nginx:*:*
cpe:2.3:a:f5:nginx_gateway_fabric:*:*:*:*:*:*:*:*
References () https://my.f5.com/manage/s/article/K000161068 - () https://my.f5.com/manage/s/article/K000161068 - Vendor Advisory
First Time F5 nginx Open Source
F5 nginx Ingress Controller
F5 nginx Instance Manager
F5 dos
F5 waf
F5 nginx Gateway Fabric
F5 nginx Plus
F5

13 May 2026, 16:27

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-13 16:16

Updated : 2026-06-29 14:17


NVD link : CVE-2026-40460

Mitre link : CVE-2026-40460

CVE.ORG link : CVE-2026-40460


JSON object : View

Products Affected

f5

  • dos
  • nginx_open_source
  • nginx_plus
  • nginx_ingress_controller
  • nginx_gateway_fabric
  • nginx_instance_manager
  • waf
CWE
CWE-290

Authentication Bypass by Spoofing