CVE-2026-50107 Details
Description
When NGINX Plus or NGINX Open Source is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in the NGINX configuration generator component of NGINX Gateway Fabric. User-supplied string values from the NginxProxy Custom Resource Definition (CRD) access log format setting are rendered directly into NGINX configuration templates without sanitization or escaping. An authenticated attacker with permission to create or modify these CRDs may craft values that inject arbitrary NGINX configuration directives. This is a control plane issue; there is no data plane exposure from the vulnerability trigger itself. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
An injection vulnerability has been identified in the NGINX configuration generator of NGINX Gateway Fabric, affecting versions 2.3.0 through 2.6.3. When NGINX Plus or NGINX Open Source is used as the data plane for NGINX Gateway Fabric, user-supplied string values from the NginxProxy Custom Resource Definition (CRD) access log format are injected directly into NGINX configuration templates without proper sanitization. This vulnerability allows an authenticated attacker with permission to modify these CRDs to inject arbitrary NGINX configuration directives. The issue is limited to the control plane, with no data plane exposure from the vulnerability trigger itself.
To address this vulnerability, users should upgrade to NGINX Gateway Fabric version 2.6.4. Additionally, it is recommended to restrict write access to NginxProxy resources via Role-based Access Control (RBAC) to trusted cluster administrators only, and to review or avoid custom access log format values from untrusted sources until patched.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 18, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://my.f5.com/manage/s/article/K000161785 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-74 | Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| f5 nginx gateway fabric | >= 2.3.0, < 2.6.4 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 22, 2026 | Initial Analysis | [email protected] |
| Jun 18, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | New CVE Received | [email protected] |