Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2834 articles · 164367 vulns · 36/41 feeds (7d)
← Back to list
8.1
CVE-2026-11311EXPLOITEDPATCHED
f5 · nginx gateway fabric

NGINX Gateway Fabric vulnerability

Description

When NGINX Plus is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in the NGINX configuration generator component of NGINX Gateway Fabric. User-supplied string values from the NginxProxy Custom Resource Definition serverTokens field and the AuthenticationFilter Custom Resource Definition extraAuthArgs field are rendered directly into NGINX configuration templates without sanitization or escaping. An authenticated attacker with permission to create or modify these Custom Resource Definitions may craft values that inject arbitrary NGINX configuration directives. This is a control plane issue; there is no data plane exposure from the vulnerability trigger itself. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected Products

VendorProductVersions
f5nginx gateway fabric2.5.0

References

  • https://my.f5.com/manage/s/article/K000161611(vendor-advisory)

Related News (1 articles)

Tier C
VulDB7h ago
CVE-2026-11311 | F5 NGINX Gateway Fabric up to 2.6.3 NGINX Configuration Generator equivalent special elements (K000161611)
→ No new info (linked only)
CVSS 3.18.1 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
2.6.4
CWECWE-76
PublishedJun 17, 2026
Last enriched7h agov2
Trending Score50
Source articles1
Independent1
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-42945EXPKEV
NGINX ngx_http_rewrite_module vulnerability
Trending: 95
HIGHCVE-2026-42530EXP
NGINX Open-Source ngx_http_v3_module vulnerability
Trending: 50
CRITICALCVE-2026-48142EXP
NGINX ngx_http_charset_module vulnerability
Trending: 48
HIGHCVE-2026-42055
NGINX ngx_http_proxy_v2_module and ngx_http_grpc_module vulnerability
Trending: 31
PRE-CVE
Multiple Vulnerabilities in F5 and NGINX Products
Trending: 20

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jun 17, 2026
Discovered by ZDM
Jun 17, 2026
Updated: description, affectedVersions, severity, activelyExploited
Jun 17, 2026
Actively Exploited
Jun 17, 2026
Patch Available
Jun 17, 2026

Version History

v2
Last enriched 7h ago
v2Tier C7h ago

Updated description with critical vulnerability details, changed severity to CRITICAL, and added affected version 2.6.3.

descriptionaffectedVersionsseverityactivelyExploited
via VulDB
v17h ago

Initial creation