CVE-2026-11311 Details
Description
When NGINX Plus is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in the NGINX configuration generator component of NGINX Gateway Fabric. User-supplied string values from the NginxProxy Custom Resource Definition serverTokens field and the AuthenticationFilter Custom Resource Definition extraAuthArgs field are rendered directly into NGINX configuration templates without sanitization or escaping. An authenticated attacker with permission to create or modify these Custom Resource Definitions may craft values that inject arbitrary NGINX configuration directives. This is a control plane issue; there is no data plane exposure from the vulnerability trigger itself. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
An injection vulnerability has been identified in the NGINX configuration generator of NGINX Gateway Fabric, specifically when NGINX Plus is used as the data plane. The vulnerability arises because user-supplied string values from the NginxProxy Custom Resource Definition (CRD) serverTokens field and the AuthenticationFilter CRD extraAuthArgs field are directly rendered into NGINX configuration templates without proper sanitization or escaping. This issue allows an authenticated attacker with permission to create or modify these CRDs to inject arbitrary NGINX configuration directives. The vulnerability is limited to the control plane, with no data plane exposure from the trigger itself.
To address this vulnerability, F5 recommends upgrading to NGINX Gateway Fabric version 2.6.4 or later. Additionally, restrict write access to the NginxProxy and AuthenticationFilter CRDs to trusted cluster administrators only, and avoid configuring custom serverTokens values or extraAuthArgs values that could be exploited.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 17, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://my.f5.com/manage/s/article/K000161611 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-74 | Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') | [email protected] |
| CWE-76 | Improper Neutralization of Equivalent Special Elements | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| f5 nginx gateway fabric | >= 2.5.0, < 2.6.4 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 2, 2026 | Initial Analysis | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | New CVE Received | [email protected] |