CVE-2026-60065 Details
Description
When NGINX Plus is configured to use the Message Queuing Telemetry Transport (MQTT) filter module (ngx_stream_mqtt_filter_module), unauthenticated attackers can send requests with conditions beyond the attacker's control to cause a heap buffer over-read in the NGINX worker process, leading to a restart. Impact: This vulnerability may allow remote unauthenticated attackers to have limited control to restart the NGINX worker process. There is no control plane exposure; this is a data plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
A heap buffer over-read vulnerability has been identified in NGINX Plus versions 37.0.0.1 to 37.0.2.1 and in the NGINX Plus 5.x version range prior to 5.9.0, when the Message Queuing Telemetry Transport (MQTT) filter module is enabled. This vulnerability allows remote, unauthenticated attackers to send requests that cause a heap buffer over-read in the NGINX worker process, leading to a process restart. This issue affects the data plane only, with no exposure to the control plane.
Users can upgrade to NGINX Plus version 37.0.3.1 or NGINX Plus 5.9.0 and above to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 15, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://my.f5.com/manage/s/article/K000162101 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-125 | Out-of-bounds Read | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| f5 nginx gateway fabric | >= 1.3.0, <= 1.6.2 >= 2.0.0, < 2.6.7 |
CPE
Remediation
| |
| f5 nginx ingress controller | >= 3.5.0, <= 3.7.2 >= 5.0.0, < 5.5.3 >= 2026-lts-r1, < 2026-lts-r4 4.0.0 4.0.1 |
CPE
Remediation
| |
| f5 nginx plus | >= 37.0.0.1, < 37.0.3.1 >= r33, < r36 r36 - r36 p1 r36 p2 r36 p3 r36 p4 r36 p5 r36 p6 |
CPE
Remediation
| |
| f5 waf | >= 4.11.0, <= 4.16.0 >= 5.2.0, <= 5.8.0 >= 5.9.0, < 5.13.4 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 10, 2026 | Initial Analysis | [email protected] |
| Jul 15, 2026 | CVE Modified | CISA-ADP |
| Jul 15, 2026 | New CVE Received | [email protected] |