Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

CVE-2026-11311: CWE-76 Improper Neutralization of Equvalent Special Elements in F5 NGINX Gateway Fabric

0
High
VulnerabilityCVE-2026-11311cvecve-2026-11311cwe-76
Published: Wed Jun 17 2026 (06/17/2026, 14:04:33 UTC)
Source: CVE Database V5
Vendor/Project: F5
Product: NGINX Gateway Fabric

Description

When NGINX Plus is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in the NGINX configuration generator component of NGINX Gateway Fabric. User-supplied string values from the NginxProxy Custom Resource Definition serverTokens field and the AuthenticationFilter Custom Resource Definition extraAuthArgs field are rendered directly into NGINX configuration templates without sanitization or escaping. An authenticated attacker with permission to create or modify these Custom Resource Definitions may craft values that inject arbitrary NGINX configuration directives. This is a control plane issue; there is no data plane exposure from the vulnerability trigger itself. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS v3.1

Score 8.1high

Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Affected software

Affected versions
2.5.0

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 06/17/2026, 15:08:16 UTC

Technical Analysis

When NGINX Plus is used as the data plane for NGINX Gateway Fabric, the configuration generator component improperly neutralizes special elements in user-supplied strings from the NginxProxy serverTokens field and the AuthenticationFilter extraAuthArgs field. These values are injected directly into NGINX configuration templates without sanitization, allowing an authenticated attacker with permission to create or modify these Custom Resource Definitions to inject arbitrary NGINX configuration directives. This is a control plane vulnerability with no direct data plane exposure. The affected version explicitly identified is 2.5.0. No official patch or remediation level has been published yet.

Potential Impact

An authenticated attacker with permission to modify specific Custom Resource Definitions can inject arbitrary NGINX configuration directives, potentially leading to control over the NGINX configuration and impacting confidentiality and integrity of the system. The vulnerability does not directly expose the data plane, and availability impact is not indicated. The CVSS score is 8.1 (high severity), reflecting network attack vector, low attack complexity, required privileges, no user interaction, and high impact on confidentiality and integrity.

Mitigation Recommendations

Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict permissions to create or modify the affected Custom Resource Definitions (NginxProxy serverTokens and AuthenticationFilter extraAuthArgs fields) to trusted administrators only to reduce the risk of exploitation.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
f5
Date Reserved
2026-06-04T18:01:54.825Z
Cvss Version
3.1
State
PUBLISHED
Remediation Level
null

Threat ID: 6a32b81b9f87a2db090fc47d

Added to database: 6/17/2026, 3:07:07 PM

Last enriched: 6/17/2026, 3:08:16 PM

Last updated: 6/17/2026, 6:23:09 PM

Views: 3

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses