CVE-2026-42946 Details
Description
A vulnerability exists in the ngx_http_scgi_module and ngx_http_uwsgi_module modules that may result in excessive memory allocation or an over-read of data. When scgi_pass or uwsgi_pass is configured, an unauthenticated attacker with man-in-the-middle (MITM) ability to control responses from an upstream server may be able to read the memory of the NGINX worker process or restart it. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
A vulnerability in the NGINX ngx_http_scgi_module and ngx_http_uwsgi_module can lead to excessive memory allocation or an over-read of data. When scgi_pass or uwsgi_pass is set up, an unauthenticated attacker with man-in-the-middle capabilities to manipulate upstream server responses may exploit this vulnerability to read the memory of the NGINX worker process or to restart it.
Users can upgrade to NGINX versions 1.31.0, 1.30.1, or NGINX Plus versions 36 P4 or 32 P6. For NGINX Instance Manager, versions 2.21.2 and 2.16.1 are recommended. F5 WAF for NGINX users should upgrade to version 5.12.1, while NGINX App Protect WAF users should move to version 5.8.0. NGINX Ingress Controller users can upgrade to version 5.4.3.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 13, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://my.f5.com/manage/s/article/K000161027 | [email protected] | MitigationVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-789 | Memory Allocation with Excessive Size Value | [email protected] |
| CWE-823 | Use of Out-of-range Pointer Offset | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| f5 dos | >= 4.3.0, <= 4.7.0 4.8.0 |
CPE
Remediation
| |
| f5 nginx gateway fabric | >= 1.3.0, <= 1.6.2 >= 2.0.0, <= 2.6.0 |
CPE
Remediation
| |
| f5 nginx ingress controller | >= 3.5.0, <= 3.7.2 >= 4.0.0, <= 4.0.1 >= 5.0.0, <= 5.4.2 |
CPE
Remediation
| |
| f5 nginx instance manager | >= 2.16.0, <= 2.22.0 |
CPE
Remediation
| |
| f5 nginx open source | >= 0.8.42, <= 0.9.7 >= 1.0.0, <= 1.30.0 |
CPE
Remediation
| |
| f5 nginx plus | >= r32, <= r36 |
CPE
Remediation
| |
| f5 waf | >= 4.9.0, <= 4.16.0 >= 5.1.0, <= 5.8.0 >= 5.9.0, <= 5.12.1 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 18, 2026 | Modified Analysis | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 16, 2026 | Initial Analysis | [email protected] |
| May 13, 2026 | New CVE Received | [email protected] |