A vulnerability exists in the ngx_http_scgi_module and ngx_http_uwsgi_module modules that may result in excessive memory allocation or an over-read of data. When scgi_pass or uwsgi_pass is configured, an unauthenticated attacker with man-in-the-middle (MITM) ability to control responses from an upstream server may be able to read the memory of the NGINX worker process or restart it. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
References
| Link | Resource |
|---|---|
| https://my.f5.com/manage/s/article/K000161027 | Mitigation Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
18 Jun 2026, 14:12
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:f5:nginx_app_protect_waf:*:*:*:*:*:*:*:* |
cpe:2.3:a:f5:dos:*:*:*:*:*:nginx:*:* |
16 Jun 2026, 19:58
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:f5:nginx_app_protect_dos:*:*:*:*:*:*:*:* cpe:2.3:a:f5:waf:*:*:*:*:*:nginx:*:* cpe:2.3:a:f5:nginx_open_source:*:*:*:*:*:*:*:* cpe:2.3:a:f5:nginx_ingress_controller:*:*:*:*:*:*:*:* cpe:2.3:a:f5:nginx_instance_manager:*:*:*:*:*:*:*:* cpe:2.3:a:f5:nginx_plus:*:*:*:*:*:*:*:* cpe:2.3:a:f5:dos:4.8.0:*:*:*:*:nginx:*:* cpe:2.3:a:f5:nginx_app_protect_waf:*:*:*:*:*:*:*:* cpe:2.3:a:f5:nginx_gateway_fabric:*:*:*:*:*:*:*:* |
|
| References | () https://my.f5.com/manage/s/article/K000161027 - Mitigation, Vendor Advisory | |
| First Time |
F5 nginx Open Source
F5 nginx Ingress Controller F5 nginx App Protect Waf F5 nginx App Protect Dos F5 nginx Instance Manager F5 dos F5 waf F5 nginx Gateway Fabric F5 nginx Plus F5 |
13 May 2026, 16:27
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-13 16:16
Updated : 2026-06-18 14:12
NVD link : CVE-2026-42946
Mitre link : CVE-2026-42946
CVE.ORG link : CVE-2026-42946
JSON object : View
Products Affected
f5
- dos
- nginx_open_source
- nginx_plus
- nginx_ingress_controller
- nginx_gateway_fabric
- nginx_instance_manager
- waf
