CVE-2026-1642: NGINX vulnerability
A vulnerability exists in NGINX OSS and NGINX Plus when configured to proxy to upstream Transport Layer Security (TLS) servers. An attacker with a man-in-the-middle (MITM) position on the upstream server side—along with conditions beyond the attacker's control—may be able to inject plain text data into the response from an upstream proxied server.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-1642?
CVE-2026-1642 has a moderate severity rating due to potential man-in-the-middle vulnerabilities in NGINX OSS and NGINX Plus.
How do I fix CVE-2026-1642?
To remediate CVE-2026-1642, upgrade to the latest patched versions of NGINX OSS or NGINX Plus as specified by F5.
Which versions of NGINX are affected by CVE-2026-1642?
CVE-2026-1642 affects various versions of NGINX OSS and NGINX Plus, particularly those configured to proxy upstream TLS servers.
Can a man-in-the-middle attack exploit CVE-2026-1642?
Yes, an attacker positioned for a man-in-the-middle attack can exploit CVE-2026-1642 under specific circumstances.
Is NGINX Ingress Controller impacted by CVE-2026-1642?
Yes, specific versions of NGINX Ingress Controller are also impacted by CVE-2026-1642.