CVE-2026-42926

When NGINX Open Source is configured to proxy HTTP/2 traffic by setting proxy_http_version to 2, and also uses proxy_set_body, an attacker may be able to inject frame headers and payload bytes to the upstream peer.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
References
Link Resource
https://my.f5.com/manage/s/article/K000161131 Mitigation Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:f5:nginx_gateway_fabric:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_open_source:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:f5:nginx_gateway_fabric:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_instance_manager:*:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:a:f5:nginx_ingress_controller:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_ingress_controller:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_ingress_controller:*:*:*:*:*:*:*:*

History

18 Jun 2026, 13:37

Type Values Removed Values Added
CPE cpe:2.3:a:f5:nginx_instance_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_open_source:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_gateway_fabric:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_ingress_controller:*:*:*:*:*:*:*:*
References () https://my.f5.com/manage/s/article/K000161131 - () https://my.f5.com/manage/s/article/K000161131 - Mitigation, Vendor Advisory
First Time F5 nginx Gateway Fabric
F5 nginx Open Source
F5 nginx Ingress Controller
F5 nginx Instance Manager
F5

13 May 2026, 16:27

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-13 16:16

Updated : 2026-06-18 13:37


NVD link : CVE-2026-42926

Mitre link : CVE-2026-42926

CVE.ORG link : CVE-2026-42926


JSON object : View

Products Affected

f5

  • nginx_ingress_controller
  • nginx_gateway_fabric
  • nginx_instance_manager
  • nginx_open_source
CWE
CWE-172

Encoding Error