CVE-2026-32682 PUBLISHED

NGINX Gateway Fabric vulnerability

Assigner: f5
Reserved: 17.06.2026 Published: 17.06.2026 Updated: 18.06.2026

When NGINX Gateway Fabric is configured using GRPCRoutes, an authenticated, remote attacker with permission to create or modify GRPCRoute resources can cause the NGINX Gateway Fabric control plane to terminate by sending undisclosed GRPCRoute configurations containing backendRef filters.

Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
CVSS Score: 7.1

Product Status

Vendor F5
Product NGINX Gateway Fabric
Versions Default: unknown
  • affected from 1.3.0 to 2.6.4 (excl.)

Credits

  • F5 finder

References

Problem Types

  • CWE-129 Improper Validation of Array Index CWE