CVE-2026-32682 Details
Description
When NGINX Gateway Fabric is configured using GRPCRoutes, an authenticated, remote attacker with permission to create or modify GRPCRoute resources can cause the NGINX Gateway Fabric control plane to terminate by sending undisclosed GRPCRoute configurations containing backendRef filters. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
A denial-of-service vulnerability has been identified in NGINX Gateway Fabric versions 1.3.0 through 1.6.2 and 2.0.0 through 2.6.3. When configured with GRPCRoutes, an authenticated, remote attacker with permission to create or modify GRPCRoute resources can disrupt the NGINX Gateway Fabric control plane. This is done by sending GRPCRoute configurations that include backendRef filters, causing the control plane process to terminate and enter a persistent crash loop. The malformed GRPCRoute resource remains in the cluster, exacerbating the issue.
To address this vulnerability, users can upgrade to NGINX Gateway Fabric version 2.6.4. For versions 1.x, no specific update is available, but users should consider upgrading to a version in the 2.x branch that includes the fix. Additionally, it is recommended to restrict role-based access control for GRPCRoutes to trusted users or deploy a ValidatingAdmissionPolicy/OPA-Gatekeeper rule that rejects GRPCRoutes with specified backendRef filters.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 18, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://my.f5.com/manage/s/article/K000161786 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-129 | Improper Validation of Array Index | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| f5 nginx gateway fabric | >= 1.3.0, <= 1.6.2 >= 2.0.0, < 2.6.4 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 2, 2026 | Initial Analysis | [email protected] |
| Jun 18, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | New CVE Received | [email protected] |