Executive brief
A vulnerability in NGINX's SCGI and uWSGI modules could allow an attacker to access sensitive information or disrupt web services. By intercepting traffic between NGINX and its backend servers, an attacker can cause the system to leak process memory or crash the worker service. This could lead to the exposure of private data or a temporary outage of the affected website or application.
Technical details
A vulnerability exists in the ngx_http_scgi_module and ngx_http_uwsgi_module modules due to improper handling of upstream responses. When scgi_pass or uwsgi_pass is configured, an unauthenticated attacker with man-in-the-middle (MITM) capabilities can manipulate responses from an upstream server to trigger excessive memory allocation (CWE-789) or an out-of-range pointer offset (CWE-823). This can result in an over-read of NGINX worker process memory or a denial-of-service condition by crashing the worker process. The attack requires the ability to control the network path between NGINX and the backend server. F5 has released security advisories detailing affected versions across their NGINX product line.
Affected products
- F5 NGINX Open Source 0.8.42 to 1.30.0
- F5 NGINX Plus r32 to r36
- F5 NGINX Ingress Controller 3.5.0 to 3.7.2, 4.0.0 to 4.0.1, 5.0.0 to 5.4.2
- F5 NGINX App Protect WAF 4.9.0 to 4.16.0, 5.1.0 to 5.12.1
- F5 NGINX Gateway Fabric 1.3.0 to 1.6.2, 2.0.0 to 2.6.0
Timeline
- 2026-05-13: advisory: Initial advisory published by F5 Networks