https://seclists.org/oss-sec/2026/q1/144: NGINX < 1.29.5, 1.28.2 MitM injection CVE-2026-1642
Published Feb 5, 2026
·Updated
Affected Software
2 affected components
Nginx NGINX Open Source>=1.3.0<1.29.5
Nginx NGINX Open Source<1.28.2
CVE-2026-1642 has been assigned a critical severity level due to its potential impact on MitM attacks.
To fix CVE-2026-1642, upgrade to NGINX version 1.29.5 or 1.28.2 or later.
CVE-2026-1642 affects NGINX versions below 1.29.5 and 1.28.2.
CVE-2026-1642 allows for potential Man-in-the-Middle (MitM) injection attacks when configured to proxy to upstream.
If you cannot upgrade, consider applying mitigations such as configuring stronger SSL/TLS settings or implementing network-level controls.