Description
When NGINX Plus is configured to use the Message Queuing Telemetry Transport (MQTT) filter module (ngx_stream_mqtt_filter_module), unauthenticated attackers can send requests with conditions beyond the attacker's control to cause a heap buffer over-read in the NGINX worker process, leading to a restart. Impact: This vulnerability may allow remote unauthenticated attackers to have limited control to restart the NGINX worker process. There is no control plane exposure; this is a data plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CVSS breakdown
CVSS 4.0
Attack Vector
Network
Attack Complexity
Low
Attack Requirements
Present
Privileges Required
None
User Interaction
None
Confidentiality (Vulnerable System)
None
Integrity (Vulnerable System)
None
Availability (Vulnerable System)
Low
Confidentiality (Subsequent System)
None
Integrity (Subsequent System)
None
Availability (Subsequent System)
None
CVSS 3.1
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
Low
Affected products
- F5 / NGINX Gateway Fabric1.3.0 – 1.6.2
- F5 / NGINX Ingress Controller4.0.0 – 4.0.0
- F5 / NGINX Ingress Controller4.0.1 – 4.0.1
- F5 / NGINX Ingress Controller3.5.0 – 3.7.2
- F5 / NGINX Ingress Controller2026-lts-r1 – 2026-lts-r4
- F5 / NGINX Plusr36 – r36
- F5 / NGINX Plusr36 – r36
- F5 / NGINX Plusr36 – r36
- F5 / NGINX Plusr36 – r36
- F5 / NGINX Plusr36 – r36
- F5 / NGINX Plusr36 – r36
- F5 / NGINX Plus37.0.0.1 – 37.0.3.1
- F5 / NGINX PlusR36 – R36 P7
- F5 / NGINX PlusR33 – *
- F5 / NGINX Plus37.0.0.1 – 37.0.3.1
- F5 / NGINX Plusr36 – r36
- F5 / waf4.11.0 – 4.16.0
References
Updated 28m ago · 8 sources