CVE-2026-1642
MediumVulnerability Description
A vulnerability exists in NGINX OSS and NGINX Plus when configured to proxy to upstream Transport Layer Security (TLS) servers. An attacker with a man-in-the-middle (MITM) position on the upstream server side—along with conditions beyond the attacker's control—may be able to inject plain text data into the response from an upstream proxied server. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CVSS Metrics
Common Vulnerability Scoring System
Vector String:
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Known Affected Software
21 configuration(s) from 1 vendor(s)
cpe:2.3:a:f5:nginx_plus:r32:p1:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_plus:r33:-:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_ingress_controller:3.7.0:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_plus:r35:-:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_ingress_controller:3.5.2:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_plus:r34:-:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_ingress_controller:3.5.1:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_ingress_controller:3.4.2:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_ingress_controller:3.6.0:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_ingress_controller:5.3.0:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_ingress_controller:3.6.2:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_ingress_controller:3.4.0:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_ingress_controller:3.4.3:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_ingress_controller:4.0.1:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_plus:r36:-:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_ingress_controller:3.4.1:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_ingress_controller:3.5.0:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_ingress_controller:3.6.1:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_ingress_controller:3.7.2:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_ingress_controller:4.0.0:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_ingress_controller:3.7.1:*:*:*:*:*:*:*
CPUAPR2026
Oracle Critical Patch Update Advisory - April 2026
CVE-2026-1642
CVE-2026-1642
USN-8038-1
USN-8038-1: nginx vulnerability
Severity Details
Weakness Type (CWE)
Acceptance of Extraneous Untrusted Data With Trusted Data
- Description
- The product, when processing trusted data, accepts any untrusted data that is also included with the trusted data, treating the untrusted data as if it were trusted.
- Typical Severity
- Medium
- Abstraction Level
- Base
Key Information
- Published Date
- February 04, 2026
