CVE-2026-32682

When NGINX Gateway Fabric is configured using GRPCRoutes, an authenticated, remote attacker with permission to create or modify GRPCRoute resources can cause the NGINX Gateway Fabric control plane to terminate by sending undisclosed GRPCRoute configurations containing backendRef filters. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
References
Link Resource
https://my.f5.com/manage/s/article/K000161786 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:f5:nginx_gateway_fabric:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_gateway_fabric:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-06-17 20:16

Updated : 2026-07-02 20:03


NVD link : CVE-2026-32682

Mitre link : CVE-2026-32682

CVE.ORG link : CVE-2026-32682


JSON object : View

Products Affected

f5

  • nginx_gateway_fabric
CWE
CWE-129

Improper Validation of Array Index