« Volver al listado

CVE-2026-60065

Estado: AnalizadaMedia (6.3)—

When NGINX Plus is configured to use the Message Queuing Telemetry Transport (MQTT) filter module (ngx_stream_mqtt_filter_module), unauthenticated attackers can send requests with conditions beyond the attacker's control to cause a heap buffer over-read in the NGINX worker process, leading to a restart.

Impact: This vulnerability may allow remote unauthenticated attackers to have limited control to restart the NGINX worker process. There is no control plane exposure; this is a data plane issue only.

Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (4)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-60065",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-60065",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-07-15T15:38:52.814250Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "f5sirt@f5.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 3.7,
          "attackVector": "NETWORK",
          "baseSeverity": "LOW",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "LOW",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 2.2
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 3.9
      }
    ],
    "cvssMetricV40": [
      {
        "type": "Secondary",
        "source": "f5sirt@f5.com",
        "cvssData": {
          "Safety": "NOT_DEFINED",
          "version": "4.0",
          "Recovery": "NOT_DEFINED",
          "baseScore": 6.3,
          "Automatable": "NOT_DEFINED",
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "valueDensity": "NOT_DEFINED",
          "vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
          "exploitMaturity": "NOT_DEFINED",
          "providerUrgency": "NOT_DEFINED",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "attackRequirements": "PRESENT",
          "privilegesRequired": "NONE",
          "subIntegrityImpact": "NONE",
          "vulnIntegrityImpact": "NONE",
          "integrityRequirement": "NOT_DEFINED",
          "modifiedAttackVector": "NOT_DEFINED",
          "subAvailabilityImpact": "NONE",
          "vulnAvailabilityImpact": "LOW",
          "availabilityRequirement": "NOT_DEFINED",
          "modifiedUserInteraction": "NOT_DEFINED",
          "modifiedAttackComplexity": "NOT_DEFINED",
          "subConfidentialityImpact": "NONE",
          "vulnConfidentialityImpact": "NONE",
          "confidentialityRequirement": "NOT_DEFINED",
          "modifiedAttackRequirements": "NOT_DEFINED",
          "modifiedPrivilegesRequired": "NOT_DEFINED",
          "modifiedSubIntegrityImpact": "NOT_DEFINED",
          "modifiedVulnIntegrityImpact": "NOT_DEFINED",
          "vulnerabilityResponseEffort": "NOT_DEFINED",
          "modifiedSubAvailabilityImpact": "NOT_DEFINED",
          "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
          "modifiedSubConfidentialityImpact": "NOT_DEFINED",
          "modifiedVulnConfidentialityImpact": "NOT_DEFINED"
        }
      }
    ]
  },
  "affected": [
    {
      "source": "f5sirt@f5.com",
      "affectedData": [
        {
          "vendor": "F5",
          "modules": [
            "ngx_stream_mqtt_filter_module"
          ],
          "product": "NGINX Plus",
          "versions": [
            {
              "status": "affected",
              "version": "37.0.0.1",
              "lessThan": "37.0.3.1",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "R36",
              "lessThan": "R36 P7",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "R33",
              "lessThan": "*",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2026-07-15T15:16:47.320",
  "references": [
    {
      "url": "https://my.f5.com/manage/s/article/K000162101",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "f5sirt@f5.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "f5sirt@f5.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-125"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "When NGINX Plus is configured to use the Message Queuing Telemetry Transport (MQTT) filter module (ngx_stream_mqtt_filter_module), unauthenticated attackers can send requests with conditions beyond the attacker's control to cause a heap buffer over-read in the NGINX worker process, leading to a restart.\n\nImpact:\nThis vulnerability may allow remote unauthenticated attackers to have limited control to restart the NGINX worker process. There is no control plane exposure; this is a data plane issue only.\n\nNote: Software versions which have reached End of Technical Support (EoTS) are not evaluated."
    }
  ],
  "lastModified": "2026-08-10T15:27:53.560",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:f5:nginx_gateway_fabric:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "15B7F1FD-0C49-460F-9CB8-23DA730EC4BE",
              "versionEndIncluding": "1.6.2",
              "versionStartIncluding": "1.3.0"
            },
            {
              "criteria": "cpe:2.3:a:f5:nginx_gateway_fabric:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0E26414B-CC24-4618-80C5-4B96013A8920",
              "versionEndExcluding": "2.6.7",
              "versionStartIncluding": "2.0.0"
            },
            {
              "criteria": "cpe:2.3:a:f5:nginx_ingress_controller:*:*:*:*:continuous_releases:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E54B5C35-49D7-43F6-B57C-4606F75192CE",
              "versionEndIncluding": "3.7.2",
              "versionStartIncluding": "3.5.0"
            },
            {
              "criteria": "cpe:2.3:a:f5:nginx_ingress_controller:*:*:*:*:continuous_releases:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2156F0F4-1515-45E7-8A13-F653F3796CAF",
              "versionEndExcluding": "5.5.3",
              "versionStartIncluding": "5.0.0"
            },
            {
              "criteria": "cpe:2.3:a:f5:nginx_ingress_controller:*:*:*:*:long-term_support:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "95CF6424-294F-41A0-B28C-B35862F3D9E5",
              "versionEndExcluding": "2026-lts-r4",
              "versionStartIncluding": "2026-lts-r1"
            },
            {
              "criteria": "cpe:2.3:a:f5:nginx_ingress_controller:4.0.0:*:*:*:continuous_releases:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "109F4C2E-4A5E-4B5E-B282-21AFD52AEC60"
            },
            {
              "criteria": "cpe:2.3:a:f5:nginx_ingress_controller:4.0.1:*:*:*:continuous_releases:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "717D820A-78A2-41EF-BB3C-5745B6D954C1"
            },
            {
              "criteria": "cpe:2.3:a:f5:nginx_plus:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A1E34F4A-5F43-4048-9216-5A8AABD33F72",
              "versionEndExcluding": "37.0.3.1",
              "versionStartIncluding": "37.0.0.1"
            },
            {
              "criteria": "cpe:2.3:a:f5:nginx_plus:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "87DE2F03-FB1E-48DC-9EEE-B3268BB4C615",
              "versionEndExcluding": "r36",
              "versionStartIncluding": "r33"
            },
            {
              "criteria": "cpe:2.3:a:f5:nginx_plus:r36:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E7E5F940-048A-446F-9A1E-074612CEA1AC"
            },
            {
              "criteria": "cpe:2.3:a:f5:nginx_plus:r36:p1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7993A0FB-BE7E-4634-BF7F-FDEE3582D3E7"
            },
            {
              "criteria": "cpe:2.3:a:f5:nginx_plus:r36:p2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "862EA47E-8D57-434E-9C8F-238325FB85B2"
            },
            {
              "criteria": "cpe:2.3:a:f5:nginx_plus:r36:p3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7B52C01B-F719-4C72-BB83-7B70EC4BC029"
            },
            {
              "criteria": "cpe:2.3:a:f5:nginx_plus:r36:p4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9F2211E4-93B9-4F1F-BA32-F5C34B879688"
            },
            {
              "criteria": "cpe:2.3:a:f5:nginx_plus:r36:p5:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "284E9DB5-02EB-40E9-9DF3-E8F8144775ED"
            },
            {
              "criteria": "cpe:2.3:a:f5:nginx_plus:r36:p6:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0680DC66-0B6F-4E86-B0E6-BCC235A837CE"
            },
            {
              "criteria": "cpe:2.3:a:f5:waf:*:*:*:*:*:nginx:*:*",
              "vulnerable": true,
              "matchCriteriaId": "021B6D53-5F4A-4A4B-AC2F-CFBEC338F69F",
              "versionEndIncluding": "4.16.0",
              "versionStartIncluding": "4.11.0"
            },
            {
              "criteria": "cpe:2.3:a:f5:waf:*:*:*:*:*:nginx:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2DB79E6C-08B0-4341-BCBE-B8070DDAA7AF",
              "versionEndIncluding": "5.8.0",
              "versionStartIncluding": "5.2.0"
            },
            {
              "criteria": "cpe:2.3:a:f5:waf:*:*:*:*:*:nginx:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4EA246F7-5222-4403-BFEA-160195FD39B2",
              "versionEndExcluding": "5.13.4",
              "versionStartIncluding": "5.9.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "f5sirt@f5.com"
}