CVE-2026-1642 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

A vulnerability exists in NGINX OSS and NGINX Plus when configured to proxy to upstream Transport Layer Security (TLS) servers. An attacker with a man-in-the-mi…
High CVSS: 8.2

CVE-2026-1642

A vulnerability exists in NGINX OSS and NGINX Plus when configured to proxy to upstream Transport Layer Security (TLS) servers. An attacker with a man-in-the-middle (MITM) position on the upstream server side—along with conditions beyond the attacker's control—may be able to inject plain text data into the response from an upstream proxied server.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Vendor
F5
Product
Nginx Gateway Fabric
CWE
CWE-349
Yayın Tarihi
2026-02-04 15:16:14
Güncelleme
2026-02-13 21:35:01
Source Identifier
f5sirt@f5.com
KEV Date Added
-

Kategoriler

Referanslar