CVE-2026-56434 Details
Description
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssi_module module. This vulnerability may exist when the Server-Side Includes (SSI), proxy_pass, and proxy_buffering off directives are configured. With this configuration, an unauthenticated attacker with man-in-the-middle (MITM) ability to control responses from an upstream server may be able to cause a use-after-free in the NGINX worker process. This issue may lead to limited modification of memory or a restart of the NGINX worker process. Impact: This vulnerability may allow remote attackers to have limited control to modify memory contents or restart the NGINX worker process. There is no control plane exposure; this is a data plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
A heap buffer over-read vulnerability has been identified in the ngx_http_ssi_module of NGINX Plus and NGINX Open Source. This issue arises when the Server-Side Includes (SSI), proxy_pass, and proxy_buffering off directives are configured. An unauthenticated attacker with man-in-the-middle capabilities to manipulate responses from an upstream server may exploit this vulnerability, potentially leading to limited memory modification or a restart of the NGINX worker process.
Users can upgrade to NGINX Plus versions 37.0.3.1 or NGINX Open Source versions 1.31.3 or 1.30.4 to address this vulnerability. For NGINX Instance Manager, versions 2.22.1 and later are recommended. In NGINX Gateway Fabric, version 2.6.7 or later should be used. For NGINX Ingress Controller, versions 2026-lts-r4 and 5.5.3 or later are advised.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 15, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://my.f5.com/manage/s/article/K000162098 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-416 | Use After Free | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| f5 nginx gateway fabric | >= 1.3.0, <= 1.6.2 >= 2.0.0, < 2.6.7 |
CPE
Remediation
| |
| f5 nginx ingress controller | >= 3.5.0, <= 3.7.2 >= 5.0.0, < 5.5.3 >= 2026-lts-r1, < 2026-lts-r4 4.0.0 4.0.1 |
CPE
Remediation
| |
| f5 nginx plus | >= 37.0.0.1, < 37.0.3.1 >= r33, < r36 r36 - r36 p1 r36 p2 r36 p3 r36 p4 r36 p5 r36 p6 |
CPE
Remediation
| |
| f5 waf | >= 4.11.0, <= 4.16.0 >= 5.2.0, <= 5.8.0 >= 5.9.0, < 5.13.4 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 10, 2026 | Initial Analysis | [email protected] |
| Jul 15, 2026 | CVE Modified | [email protected] |
| Jul 15, 2026 | CVE Modified | CISA-ADP |
| Jul 15, 2026 | New CVE Received | [email protected] |