CVE Vulnerabilities

CVE-2026-1642

Acceptance of Extraneous Untrusted Data With Trusted Data

Published: Feb 04, 2026 | Modified: Feb 13, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
5.9 MODERATE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

A vulnerability exists in NGINX OSS and NGINX Plus when configured to proxy to upstream Transport Layer Security (TLS) servers. An attacker with a man-in-the-middle (MITM) position on the upstream server side—along with conditions beyond the attackers control—may be able to inject plain text data into the response from an upstream proxied server.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Weakness

The product, when processing trusted data, accepts any untrusted data that is also included with the trusted data, treating the untrusted data as if it were trusted.

Affected Software

NameVendorStart VersionEnd Version
Nginx_gateway_fabricF51.2.0 (including)1.6.2 (including)
Nginx_gateway_fabricF52.0.0 (including)2.4.1 (excluding)
Nginx_ingress_controllerF53.4.0 (including)3.7.2 (including)
Nginx_ingress_controllerF54.0.0 (including)4.0.1 (including)
Nginx_ingress_controllerF55.0.0 (including)5.3.3 (excluding)
Nginx_instance_managerF52.15.1 (including)2.21.0 (including)
Nginx_open_sourceF51.3.0 (including)1.28.2 (excluding)
Nginx_open_sourceF51.29.0 (including)1.29.5 (excluding)
Nginx_plusF5r33 (including)r35 (excluding)
Nginx_plusF5r32 (including)r32 (including)
Nginx_plusF5r32-p1 (including)r32-p1 (including)
Nginx_plusF5r32-p2 (including)r32-p2 (including)
Nginx_plusF5r32-p3 (including)r32-p3 (including)
Nginx_plusF5r33-p1 (including)r33-p1 (including)
Nginx_plusF5r33-p2 (including)r33-p2 (including)
Nginx_plusF5r33-p3 (including)r33-p3 (including)
Nginx_plusF5r34-p1 (including)r34-p1 (including)
Nginx_plusF5r34-p2 (including)r34-p2 (including)
Nginx_plusF5r35 (including)r35 (including)
Nginx_plusF5r36 (including)r36 (including)
Nginx_plusF5r36-p1 (including)r36-p1 (including)
NginxUbuntudevel*
NginxUbuntujammy*
NginxUbuntunoble*
NginxUbuntuquesting*
NginxUbuntuupstream*

References