PT-2026-50533 · F5 · Nginx Gateway Fabric

CVE-2026-32682

·

Published

2026-06-17

·

Updated

2026-07-02

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions NGINX Gateway Fabric (affected versions not specified)
Description When configured using GRPCRoutes, an authenticated remote attacker with permissions to create or modify GRPCRoute resources can cause the control plane to terminate. This occurs by sending specific GRPCRoute configurations that include backendRef filters.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Validation of Array Index

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-08559
BIT-NGINX-GATEWAY-FABRIC-2026-32682
CVE-2026-32682

Affected Products

Nginx Gateway Fabric