CVE-2026-11311
published 2026-06-17CVE-2026-11311: When NGINX Plus is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in the NGINX configuration generator component of…
PriorityP343medium6.5CVSS 3.1
AVNACLPRLUINSUCNIHAN
EPSS
0.57%
43.7th percentile
When NGINX Plus is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in the NGINX configuration generator component of NGINX Gateway Fabric. User-supplied string values from the NginxProxy Custom Resource Definition serverTokens field and the AuthenticationFilter Custom Resource Definition extraAuthArgs field are rendered directly into NGINX configuration templates without sanitization or escaping. An authenticated attacker with permission to create or modify these Custom Resource Definitions may craft values that inject arbitrary NGINX configuration directives. This is a control plane issue; there is no data plane exposure from the vulnerability trigger itself.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| f5 | nginx_gateway_fabric | >= 2.5.0 < 2.6.4 | 2.6.4 |
| f5 | nginx_gateway_fabric | >= 2.5.0 < 2.6.4 | 2.6.4 |
| f5 | nginx_plus | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
nvdv4.08.6HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
cvelistv5v3.18.1HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
F5
CVE-2026-11311: When NGINX Plus is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in the NG...
vendor_f5·2026-06-17·CVSS 8.1
CVE-2026-11311 [HIGH] CWE-76 CVE-2026-11311: When NGINX Plus is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in the NG...
CVE-2026-11311: When NGINX Plus is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in the NG...
When NGINX Plus is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in the NGINX configuration generator component of NGINX Gateway Fabric. User-supplied string values from the NginxProxy Custom Resource Definition serverTokens field and the AuthenticationFilter Custom Resource Definition extraAuthArgs field are rendered directly into NGINX configuration templates without sanitization or escaping. An authenticated attacker with permission to create or modify these Custom Resource Definitions may craft values that inject arbitrary NGINX configuration directives. This is a control plane issue; there is no data plane
GHSA
When NGINX Plus is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in the NGINX configuration generator component of NGINX Gateway Fabric.
ghsa_unreviewed·2026-06-17
CVE-2026-11311 [HIGH] CWE-76 When NGINX Plus is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in the NGINX configuration generator component of NGINX Gateway Fabric.
When NGINX Plus is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in the NGINX configuration generator component of NGINX Gateway Fabric. User-supplied string values from the NginxProxy Custom Resource Definition serverTokens field and the AuthenticationFilter Custom Resource Definition extraAuthArgs field are rendered directly into NGINX configuration templates without sanitization or escaping. An authenticated attacker with permission to create or modify these Custom Resource Definitions may craft values that inject arbitrary NGINX configuration directives. This is a control plane issue; there is no data plane exposure from the vulnerability trigger itself.
Note: Software versions which have reached End of Technical Support (EoTS) are not evalu
CVEList
NGINX Gateway Fabric vulnerability
cvelistv5·2026-06-17·CVSS 8.1
CVE-2026-11311 [HIGH] CWE-76 NGINX Gateway Fabric vulnerability
NGINX Gateway Fabric vulnerability
When NGINX Plus is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in the NGINX configuration generator component of NGINX Gateway Fabric. User-supplied string values from the NginxProxy Custom Resource Definition serverTokens field and the AuthenticationFilter Custom Resource Definition extraAuthArgs field are rendered directly into NGINX configuration templates without sanitization or escaping. An authenticated attacker with permission to create or modify these Custom Resource Definitions may craft values that inject arbitrary NGINX configuration directives. This is a control plane issue; there is no data plane exposure from the vulnerability trigger itself.
Note: Software versions which have reached End of Te
VulDB
F5 NGINX Gateway Fabric up to 2.6.3 NGINX Configuration Generator equivalent special elements (K000161611)
vuldb·2026-06-17
CVE-2026-11311 [CRITICAL] F5 NGINX Gateway Fabric up to 2.6.3 NGINX Configuration Generator equivalent special elements (K000161611)
A vulnerability categorized as critical has been discovered in F5 NGINX Gateway Fabric up to 2.6.3. Affected is an unknown function of the component NGINX Configuration Generator. The manipulation results in improper neutralization of equivalent special elements.
This vulnerability is known as CVE-2026-11311. It is possible to launch the attack remotely. No exploit is available.
It is advisable to upgrade the affected component.
No detection rules found.
No public exploits indexed.
2026-06-17
Published