Junglewise Threat Intelligence

CVE-2026-42926: F5 NGINX Open Source header injection in HTTP/2 proxying

CVE-2026-42926 · Severity: medium · CVSS 5.8 · Published 2026-05-13

Technologies: F5 Nginx Ingress Controller, F5 NGINX Instance Manager, F5 Nginx Gateway Fabric, NGINX Open Source. Vendors: F5, NGINX.

Executive brief

NGINX Open Source and related NGINX products are vulnerable to a security flaw when configured to handle HTTP/2 traffic in a specific way. An attacker can exploit this to inject unauthorized data or headers into the communication between NGINX and the backend servers it manages. This could lead to data integrity issues or the bypass of certain security controls within the internal network.

Technical details

The vulnerability is classified as an encoding error (CWE-172) within the ngx_http_proxy_v2_module. It occurs when NGINX is configured to proxy HTTP/2 traffic (proxy_http_version 2) and simultaneously uses the 'proxy_set_body' directive. An unauthenticated remote attacker can exploit this configuration to inject arbitrary frame headers and payload bytes into the stream sent to the upstream peer. This could potentially be used for request smuggling or bypassing security filters. The issue is addressed in NGINX Open Source version 1.31.0 and various patched versions of F5's NGINX-based products.

Affected products

  • F5 NGINX Open Source 1.29.4 to 1.30.0
  • F5 NGINX Gateway Fabric 1.3.0 to 1.6.2, 2.0.0 to 2.6.0
  • F5 NGINX Ingress Controller 3.5.0 to 3.7.2, 4.0.0 to 4.0.1, 5.0.0 to 5.4.2
  • F5 NGINX Instance Manager 2.16.0 to 2.22.0

Timeline

  • 2026-05-13: disclosed
  • 2026-05-13: advisory

References

Related threats