Junglewise Threat Intelligence

CVE-2026-32682: F5 NGINX Gateway Fabric DoS in GRPCRoute backendRef filters

CVE-2026-32682 · Severity: medium · CVSS 6.5 · Published 2026-06-17

Technologies: F5 Nginx Gateway Fabric. Vendors: F5.

Executive brief

F5 NGINX Gateway Fabric, a tool used to manage network traffic for modern applications, contains a vulnerability that can cause its control system to crash. An authorized user with the ability to configure traffic routing can send a specifically crafted request that forces the system to shut down. This results in a denial-of-service condition, potentially disrupting the management of network traffic and application availability.

Technical details

A denial-of-service vulnerability exists in NGINX Gateway Fabric when configured with GRPCRoutes. The issue is caused by improper validation of array indexes (CWE-129) within the control plane when processing GRPCRoute configurations that contain backendRef filters. An authenticated remote attacker with the necessary Kubernetes RBAC permissions to create or modify GRPCRoute resources can submit a crafted configuration that triggers a process termination. This affects versions 1.3.0 through 2.6.3; users should update to version 2.6.4 or later to resolve the issue.

Affected products

  • F5 NGINX Gateway Fabric 1.3.0 to 2.6.3

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory

References

Related threats