Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-1642

26
FAUCET Score

CVE-2026-1642 describes a medium-severity vulnerability in NGINX OSS and NGINX Plus, as well as several related F5 products, when configured to proxy to upstream TLS servers. A man-in-the-middle attacker on the upstream side could potentially inject plaintext data into the proxied server's response, though this requires specific conditions beyond the attacker's control. The CVSS score of 5.9 reflects a network attack vector with high attack complexity, leading to a high impact on integrity but no impact on confidentiality or availability. There is no evidence of active exploitation, public exploit code, or inclusion in the CISA KEV catalog, though it has garnered some community discussion and media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
>= 1.2.0, <= 1.6.2CPE matchmatch criteria
cpe:2.3:a:f5:nginx_gateway_fabric:*:*:*:*:*:*:*:*
>= 2.0.0, < 2.4.1CPE matchmatch criteria
cpe:2.3:a:f5:nginx_gateway_fabric:*:*:*:*:*:*:*:*
>= 3.4.0, <= 3.7.2CPE matchmatch criteria
cpe:2.3:a:f5:nginx_ingress_controller:*:*:*:*:*:*:*:*
>= 4.0.0, <= 4.0.1CPE matchmatch criteria
cpe:2.3:a:f5:nginx_ingress_controller:*:*:*:*:*:*:*:*
>= 5.0.0, < 5.3.3CPE matchmatch criteria
cpe:2.3:a:f5:nginx_ingress_controller:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

8.2HIGH

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
PRESENT
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
NONE
VS Integrity
HIGH
VS Availability
NONE
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.34%
Probability of exploitation in next 30 days
EPSS Percentile
26.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0034 is in the 3rd percentile among its peer group of 19,956 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (41)

3cxpatch availablevia llm_extracted
apolloconfigpatch availablevia llm_extracted
authlibpatch availablevia llm_extracted
axllentpatch availablevia llm_extracted
bacnetstackpatch availablevia llm_extracted
boschpatch availablevia llm_extracted
broadcompatch availablevia llm_extracted
caddypatch availablevia llm_extracted
clamavpatch availablevia llm_extracted
clastixpatch availablevia llm_extracted
debianpatch availablevia llm_extracted
debianpatch availablevia llm_extracted
Fixed in: 3.13.0.2
View patch
denopatch availablevia llm_extracted
dhis2patch availablevia llm_extracted
ffmpegpatch availablevia llm_extracted
filerisepatch availablevia llm_extracted
kamailiopatch availablevia llm_extracted
kongpatch availablevia llm_extracted
maxkbpatch availablevia llm_extracted
nessuspatch availablevia llm_extracted
netgearpatch availablevia llm_extracted
Fixed in: 1.29.5+, 1.28.2+
nomadpatch availablevia llm_extracted
opensshpatch availablevia llm_extracted
Fixed in: 1.29.5
View patch
pi_holepatch availablevia llm_extracted
posthogpatch availablevia llm_extracted
power_bipatch availablevia llm_extracted
Fixed in: 1.28.2
proxmoxpatch availablevia llm_extracted
stripepatch availablevia llm_extracted
terraformpatch availablevia llm_extracted
Fixed in: 1.29.5
tolgeepatch availablevia llm_extracted
Fixed in: 3.13.0.2
dahuavendor investigatingvia llm_extracted
Fixed in: 1.28.2+
dfinityvendor investigatingvia llm_extracted
Fixed in: 1.29.5
jfrogvendor investigatingvia llm_extracted
Fixed in: 1.29.5
liferayvendor investigatingvia llm_extracted
Fixed in: 1.28.2
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: nginx
redhatno patchvia redhat_api
Product: Red Hat Lightspeed proxy 1Fixed in: insights-proxy/insights-proxy-container-rhel9
redhatno patchvia redhat_api
Product: Red Hat Hardened ImagesFixed in: nginx
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: nginx:1.26/nginx
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: nginx:1.24/nginx
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: nginx
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: nginx:1.24/nginx

Vendor Advisories (37)

tolgeellm-tolgee-dff3bc670d619f27HIGH

Nginx patch for man-in-the-middle upstream response injection

Mar 10, 2026
debianllm-debian-b70c6237b6f9a9cf

Nginx man-in-the-middle upstream response injection

Mar 10, 2026
redhatCVE-2026-1642Moderate

nginx: NGINX: Data injection via man-in-the-middle attack on TLS proxied connections

Feb 4, 2026
opensshllm-openssh-d6e8158a623093a4MEDIUM

SSL upstream injection

Jan 1, 2026
power_billm-power_bi-62c5e748d5fb95b1MEDIUM

SSL upstream injection

Jan 1, 2026
dfinityllm-dfinity-5e9aaedc2a8d9d7dMEDIUM

SSL upstream injection

Jan 1, 2026
axllentllm-axllent-79946a4cdb70afbb

Man-in-the-middle upstream response injection in Nginx

stripellm-stripe-1d75c2716142fcef

Man-in-the-middle upstream response injection in Nginx

nessusllm-nessus-b0a05e4d0caa0ab6HIGH

Nginx Man-in-the-Middle Upstream Response Injection

ffmpegllm-ffmpeg-4120d7f3e35abadfHIGH

Nginx Man-in-the-Middle Upstream Response Injection Vulnerability

bacnetstackllm-bacnetstack-751dfc5760757fc6CRITICAL

Man-in-the-middle upstream response injection in Nginx

kongllm-kong-e56ba40492992c60HIGH

Nginx man-in-the-middle upstream response injection

debianllm-debian-2655e6fa9c3a19bdHIGH

Nginx man-in-the-middle upstream response injection vulnerability

filerisellm-filerise-de5031dca147373dHIGH

Nginx patch for a man-in-the-middle upstream response injection

kamailiollm-kamailio-76135bbdf632ab4f

Man-in-the-middle upstream response injection in Nginx

apolloconfigllm-apolloconfig-845a776f044ce9b8

Man-in-the-middle upstream response injection in Nginx

boschllm-bosch-4023ced7bef3318fCRITICAL

Nginx man-in-the-middle upstream response injection vulnerability

clamavllm-clamav-1af7062079f434e7

Nginx man-in-the-middle upstream response injection vulnerability

denollm-deno-d69c1fde718d67ccHIGH

Nginx Man-in-the-Middle Upstream Response Injection Vulnerability

3cxllm-3cx-e8425bf5a6632ee2

Man-in-the-middle upstream response injection in Nginx

dhis2llm-dhis2-f894fe8bbcc0390c

Man-in-the-middle upstream response injection in Nginx

clastixllm-clastix-f54e1b67341d1bbc

Nginx patch for a man-in-the-middle upstream response injection

caddyllm-caddy-4e71edacf93080e7

Nginx man-in-the-middle upstream response injection

proxmoxllm-proxmox-29b385d9d5e0dd19HIGH

Nginx man-in-the-middle upstream response injection

netgearllm-netgear-5f3c44bb5cc3051bMEDIUM

SSL upstream injection

liferayllm-liferay-9c9e08e1a49e4476MEDIUM

SSL upstream injection

jfrogllm-jfrog-e40f75097be8ae94MEDIUM

SSL upstream injection

dahuallm-dahua-4da1d919bc3fc9b7MEDIUM

SSL upstream injection

proxmoxllm-proxmox-7188f8baa024cb9e

Nginx man-in-the-middle upstream response injection vulnerability

pi_holellm-pi_hole-9c47c16917e12863HIGH

Nginx man-in-the-middle upstream response injection vulnerability

authlibllm-authlib-b6fe3506ced1fda7

Man-in-the-middle upstream response injection in Nginx

nessusllm-nessus-03e7022d0306f14f

Man-in-the-middle upstream response injection in Nginx

terraformllm-terraform-f64bd1598d3bac8eMEDIUM

SSL upstream injection

broadcomllm-broadcom-f2e085506caad712HIGH

Nginx man-in-the-middle upstream response injection vulnerability

posthogllm-posthog-0fd7ff6146cf830bHIGH

Nginx man-in-the-middle upstream response injection vulnerability

maxkbllm-maxkb-72e389725b1c471bHIGH

Man-in-the-middle upstream response injection in Nginx

nomadllm-nomad-1699998f572ca7a6HIGH

Nginx man-in-the-middle upstream response injection vulnerability

References

openwall.com / lists/oss-security/2026/02/05/1
Mailing ListThird Party Advisory
my.f5.com / manage/s/article/K000159824
Vendor Advisory