Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2026-56434 Details

Description

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssi_module module. This vulnerability may exist when the Server-Side Includes (SSI), proxy_pass, and proxy_buffering off directives are configured. With this configuration, an unauthenticated attacker with man-in-the-middle (MITM) ability to control responses from an upstream server may be able to cause a use-after-free in the NGINX worker process. This issue may lead to limited modification of memory or a restart of the NGINX worker process. Impact: This vulnerability may allow remote attackers to have limited control to modify memory contents or restart the NGINX worker process. There is no control plane exposure; this is a data plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Metrics

CVSS 3.x Severity and Vector Strings:

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

Weakness Enumeration

CWE-IDCWE NameSource
CWE-416Use After Free[email protected]

Affected Products

ProductVersions
f5 nginx gateway fabric
>= 1.3.0, <= 1.6.2
>= 2.0.0, < 2.6.7

CPE

  • cpe:2.3:a:f5:nginx_gateway_fabric:*:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
f5 nginx ingress controller
>= 3.5.0, <= 3.7.2
>= 5.0.0, < 5.5.3
>= 2026-lts-r1, < 2026-lts-r4
4.0.0
4.0.1

CPE

  • cpe:2.3:a:f5:nginx_ingress_controller:*:*:*:*:continuous_releases:*:*:*
  • cpe:2.3:a:f5:nginx_ingress_controller:*:*:*:*:long-term_support:*:*:*
  • cpe:2.3:a:f5:nginx_ingress_controller:4.0.0:*:*:*:continuous_releases:*:*:*
  • cpe:2.3:a:f5:nginx_ingress_controller:4.0.1:*:*:*:continuous_releases:*:*:*

Remediation

  • No remediation found in references.
f5 nginx plus
>= 37.0.0.1, < 37.0.3.1
>= r33, < r36
r36 -
r36 p1
r36 p2

CPE

  • cpe:2.3:a:f5:nginx_plus:*:*:*:*:*:*:*:*
  • cpe:2.3:a:f5:nginx_plus:r36:-:*:*:*:*:*:*
  • cpe:2.3:a:f5:nginx_plus:r36:p1:*:*:*:*:*:*
  • cpe:2.3:a:f5:nginx_plus:r36:p2:*:*:*:*:*:*
  • cpe:2.3:a:f5:nginx_plus:r36:p3:*:*:*:*:*:*
  • cpe:2.3:a:f5:nginx_plus:r36:p4:*:*:*:*:*:*
  • cpe:2.3:a:f5:nginx_plus:r36:p5:*:*:*:*:*:*
  • cpe:2.3:a:f5:nginx_plus:r36:p6:*:*:*:*:*:*

Remediation

  • No remediation found in references.
f5 waf
>= 4.11.0, <= 4.16.0
>= 5.2.0, <= 5.8.0
>= 5.9.0, < 5.13.4

CPE

  • cpe:2.3:a:f5:waf:*:*:*:*:*:nginx:*:*

Remediation

  • No remediation found in references.

Change History

4 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2026-56434
NVD Published Date:
Jul 15, 2026
NVD Last Modified:
Aug 10, 2026
Source:
[email protected]
CVE-2026-56434 Details - Not Deferred