Executive brief
F5 NGINX Gateway Fabric, a tool used to manage network traffic for modern applications, contains a vulnerability that can cause its control system to crash. An authorized user with the ability to configure traffic routing can send a specifically crafted request that forces the system to shut down. This results in a denial-of-service condition, potentially disrupting the management of network traffic and application availability.
Technical details
A denial-of-service vulnerability exists in NGINX Gateway Fabric when configured with GRPCRoutes. The issue is caused by improper validation of array indexes (CWE-129) within the control plane when processing GRPCRoute configurations that contain backendRef filters. An authenticated remote attacker with the necessary Kubernetes RBAC permissions to create or modify GRPCRoute resources can submit a crafted configuration that triggers a process termination. This affects versions 1.3.0 through 2.6.3; users should update to version 2.6.4 or later to resolve the issue.
Affected products
- F5 NGINX Gateway Fabric 1.3.0 to 2.6.3
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory