When NGINX Plus is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in the NGINX configuration generator component of NGINX Gateway Fabric. User-supplied string values from the Authentication Filter Custom Resource Definition clientID or cookieName fields, or in the clientSecret field of a Secret referenced by an Authentication Filter, are rendered directly into NGINX configuration templates without sanitization or escaping.
Impact:
An authenticated attacker with permission to create or modify these resources may craft values that inject arbitrary NGINX configuration directives. This is a control plane issue; there is no data plane exposure.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
As this attack is conducted by authenticated users with Kubernetes role-based access control (RBAC) write access to the affected CRDs, the only complete mitigation is to restrict that access to fully trusted administrators only.
| Link | Providers |
|---|---|
| https://my.f5.com/manage/s/article/K000162600 |
|
Thu, 03 Sep 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
F5
F5 nginx Gateway Fabric |
|
| Vendors & Products |
F5
F5 nginx Gateway Fabric |
Wed, 02 Sep 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 02 Sep 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Description: When NGINX Plus is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in the NGINX configuration generator component of NGINX Gateway Fabric. User-supplied string values from the Authentication Filter Custom Resource Definition clientID or cookieName fields, or in the clientSecret field of a Secret referenced by an Authentication Filter, are rendered directly into NGINX configuration templates without sanitization or escaping. Impact: An authenticated attacker with permission to create or modify these resources may craft values that inject arbitrary NGINX configuration directives. This is a control plane issue; there is no data plane exposure. | |
| Title | NGF vulnerability | |
| Weaknesses | CWE-76 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: f5
Published:
Updated: 2026-09-03T03:56:36.276Z
Reserved: 2026-07-30T21:15:36.935Z
Link: CVE-2026-66362
Updated: 2026-09-02T17:57:22.186Z
Status : Awaiting Analysis
Published: 2026-09-02T16:17:18.663
Modified: 2026-09-02T19:23:13.660
Link: CVE-2026-66362
No data.
OpenCVE Enrichment
Updated: 2026-09-03T10:00:11Z