Executive brief
NGINX Plus is a high-performance application delivery platform and web server. A vulnerability in its MQTT filter module allows an unauthenticated remote attacker to crash the NGINX worker process. While this can cause temporary service interruptions as the process restarts, it does not expose sensitive data or the management control plane.
Technical details
An out-of-bounds read (CWE-125) exists in the ngx_stream_mqtt_filter_module of NGINX Plus. The vulnerability is triggered when the module is configured and an unauthenticated attacker sends specifically crafted MQTT requests that create conditions leading to a heap buffer over-read. This results in the termination and subsequent restart of the NGINX worker process, impacting availability. The attack requires the MQTT filter to be active and has a high attack complexity as the conditions are partially beyond the attacker's direct control. Patches are available in versions 37.0.3.1 and R36 P7.
Affected products
- F5 NGINX Plus 37.0.0.1 to 37.0.3.1, R36 before R36 P7, R33 and later
Timeline
- 2026-07-15: advisory: F5 published security advisory K000162101
- 2026-07-15: disclosed: CVE-2026-60065 published to NVD