BIT-nginx-gateway-fabric-2026-32682

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/nginx-gateway-fabric/BIT-nginx-gateway-fabric-2026-32682.json
JSON Data
https://api.test.osv.dev/v1/vulns/BIT-nginx-gateway-fabric-2026-32682
Aliases
  • CVE-2026-32682
Published
2026-06-24T11:07:08Z
Modified
2026-09-08T08:47:32Z
Summary
NGINX Gateway Fabric vulnerability
Details

When NGINX Gateway Fabric is configured using GRPCRoutes, an authenticated, remote attacker with permission to create or modify GRPCRoute resources can cause the NGINX Gateway Fabric control plane to terminate by sending undisclosed GRPCRoute configurations containing backendRef filters.

Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Database specific
{
    "cpes": [
        "cpe:2.3:a:f5:nginx_gateway_fabric:*:*:*:*:*:*:*:*"
    ],
    "severity": "High"
}
References

Affected packages

Bitnami / nginx-gateway-fabric

Package

Name
nginx-gateway-fabric
Purl
pkg:bitnami/nginx-gateway-fabric

Severity

  • 7.1 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
1.3.0
Fixed
2.6.4

Database specific

source
"https://github.com/bitnami/vulndb/tree/main/data/nginx-gateway-fabric/BIT-nginx-gateway-fabric-2026-32682.json"