F5 Patches Critical NGINX Vulnerability CVE-2023-50438
Key Takeaways F5 has released an urgent out-of-band security advisory addressing several critical and high-severity vulnerabilities in NGINX products. The flaws affect NGINX Open Source, NGINX Plus,...
Key Takeaways
- F5 has released an urgent out-of-band security advisory addressing several critical and high-severity vulnerabilities in NGINX products.
- The flaws affect NGINX Open Source, NGINX Plus, NGINX Gateway Fabric, and NGINX Ingress Controller.
- Attackers could exploit these vulnerabilities to achieve remote code execution, memory corruption, or denial-of-service (DoS) conditions.
- Patches are available for most affected core NGINX components, with CVSS v4.0 scores reaching up to 9.2.
- Organizations are strongly advised to update immediately and apply mitigations for products awaiting direct fixes.
F5 has issued an urgent out-of-band security advisory, detailing multiple high-severity vulnerabilities discovered across its NGINX product line. These critical flaws could potentially allow malicious actors to execute arbitrary code remotely or launch debilitating denial-of-service (DoS) attacks against affected systems.
Table Of Content
Published on June 17, 2026, the advisory highlights significant risks impacting NGINX Open Source, NGINX Plus, and related offerings such as NGINX Gateway Fabric and NGINX Ingress Controller.
Several of the identified vulnerabilities carry CVSS v4.0 scores as high as 9.2, underscoring the severe threat they pose to organizations that depend on NGINX for their web and application delivery infrastructure.
Critical Vulnerabilities Detailed
One of the most pressing issues, identified as CVE-2026-42530, resides within the ngx_http_v3_module of NGINX. This particular vulnerability impacts NGINX Open Source versions 1.31.0 and 1.31.1 and has since been addressed in version 1.31.2.
Successful exploitation of CVE-2026-42530 could result in memory corruption, opening avenues for remote code execution or significant service disruptions. Another notable high-risk vulnerability, CVE-2026-42055, affects both the ngx_http_proxy_v2_module and ngx_http_grpc_module.
This flaw impacts both NGINX Open Source and NGINX Plus deployments. Cybersecurity researchers caution that attackers could leverage this vulnerability to trigger DoS conditions or execute arbitrary malicious code, particularly under specific configuration settings.
F5 Releases Patches and Mitigations
F5 has released fixes for the most critical NGINX vulnerabilities. NGINX Open Source versions 1.30.3 and 1.31.2 contain resolutions, as do NGINX Plus release 37.0.2.1 and R36 P6.
The advisory also revealed additional high-severity vulnerabilities in NGINX Gateway Fabric, specifically CVE-2026-11311 and CVE-2026-50107. These issues affect versions 2.3.0 through 2.6.3 and have been mitigated in version 2.6.4.
Exploiting these Gateway Fabric vulnerabilities could lead to service instability or unauthorized operations within Kubernetes environments where the fabric is deployed.
Beyond the critical and high-severity flaws, the advisory also includes medium-severity vulnerabilities, such as CVE-2026-48142, which affects the ngx_http_charset_module. While less severe, this issue could still be exploited to alter application behavior or degrade service reliability if left unpatched.
It is important to note that several related F5 and NGINX products, including NGINX Instance Manager, NGINX App Protect, and F5 WAF for NGINX, are also affected but do not yet have direct patches available. F5 recommends implementing interim mitigations and closely monitoring configurations for these components until official fixes are released.
Security experts stress the widespread deployment of NGINX in modern web infrastructure, making these vulnerabilities especially attractive targets for cyber attackers. The F5 Advisory K000161614 explicitly warns that internet-facing systems are at the highest risk and must be updated to the latest patched versions without delay.
For situations where immediate upgrades are not feasible, administrators are advised to implement temporary mitigations, such as restricting network access, disabling vulnerable modules, and diligently monitoring system logs for any suspicious activities. This out-of-band release highlights the critical nature of these vulnerabilities and their potential impact on production systems. Given the combination of remote exploitation potential and high severity scores, prompt patching is essential to reduce the overall attack surface.
F5 continues to provide ongoing updates and comprehensive technical guidance via its official advisory portal. Users are strongly encouraged to subscribe to security notifications to remain informed about future vulnerabilities.
What You Should Do
- Immediately Apply Patches: Update NGINX Open Source to versions 1.30.3 or 1.31.2, NGINX Plus to release 37.0.2.1 or R36 P6, and NGINX Gateway Fabric to version 2.6.4.
- Implement Mitigations: For affected products without direct patches (e.g., NGINX Instance Manager, NGINX App Protect, F5 WAF for NGINX), apply recommended temporary mitigations such as restricting access, disabling vulnerable modules, and enhancing log monitoring.
- Monitor Systems: Continuously monitor logs for any signs of suspicious activity or attempted exploitation, especially on internet-facing NGINX deployments.
- Stay Informed: Subscribe to F5 security notifications and regularly check the official F5 advisory portal for further updates and guidance.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.