CVE-2026-42946

A vulnerability exists in the ngx_http_scgi_module and ngx_http_uwsgi_module modules that may result in excessive memory allocation or an over-read of data. When scgi_pass or uwsgi_pass is configured, an unauthenticated attacker with man-in-the-middle (MITM) ability to control responses from an upstream server may be able to read the memory of the NGINX worker process or restart it.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
References
Link Resource
https://my.f5.com/manage/s/article/K000161027 Mitigation Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:f5:dos:*:*:*:*:*:nginx:*:*
cpe:2.3:a:f5:dos:4.8.0:*:*:*:*:nginx:*:*
cpe:2.3:a:f5:nginx_gateway_fabric:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_gateway_fabric:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_ingress_controller:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_ingress_controller:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_ingress_controller:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_instance_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_open_source:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_open_source:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_plus:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:waf:*:*:*:*:*:nginx:*:*
cpe:2.3:a:f5:waf:*:*:*:*:*:nginx:*:*
cpe:2.3:a:f5:waf:*:*:*:*:*:nginx:*:*

History

18 Jun 2026, 14:12

Type Values Removed Values Added
CPE cpe:2.3:a:f5:nginx_app_protect_dos:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_app_protect_waf:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:dos:*:*:*:*:*:nginx:*:*

16 Jun 2026, 19:58

Type Values Removed Values Added
CPE cpe:2.3:a:f5:nginx_app_protect_dos:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:waf:*:*:*:*:*:nginx:*:*
cpe:2.3:a:f5:nginx_open_source:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_ingress_controller:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_instance_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_plus:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:dos:4.8.0:*:*:*:*:nginx:*:*
cpe:2.3:a:f5:nginx_app_protect_waf:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_gateway_fabric:*:*:*:*:*:*:*:*
References () https://my.f5.com/manage/s/article/K000161027 - () https://my.f5.com/manage/s/article/K000161027 - Mitigation, Vendor Advisory
First Time F5 nginx Open Source
F5 nginx Ingress Controller
F5 nginx App Protect Waf
F5 nginx App Protect Dos
F5 nginx Instance Manager
F5 dos
F5 waf
F5 nginx Gateway Fabric
F5 nginx Plus
F5

13 May 2026, 16:27

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-13 16:16

Updated : 2026-06-18 14:12


NVD link : CVE-2026-42946

Mitre link : CVE-2026-42946

CVE.ORG link : CVE-2026-42946


JSON object : View

Products Affected

f5

  • dos
  • nginx_open_source
  • nginx_plus
  • nginx_ingress_controller
  • nginx_gateway_fabric
  • nginx_instance_manager
  • waf
CWE
CWE-789

Memory Allocation with Excessive Size Value

CWE-823

Use of Out-of-range Pointer Offset