CVE-2026-9256
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite directive uses a regex pattern with distinct, overlapping Perl-Compatible Regular Expression (PCRE) captures (for example, ^/((.*))$) and a replacement string that references multiple such captures (for example, $1$2) in a redirect or arguments context. An unauthenticated attacker along with conditions beyond their control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR.
Leer descripción completaMostrar menos
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CVSS
- Versión: 4.0
- Vector: CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Puntuación base: 9.2
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 2.70%
- Percentil entre todas las CVEs puntuadas: 85
- Fecha de la puntuación: 1/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (12)
CWE
- CWE-122
- CWE-122
Referencias
- https://my.f5.com/manage/s/article/K000161377
- http://www.openwall.com/lists/oss-security/2026/05/22/14
- https://lists.debian.org/debian-lts-announce/2026/06/msg00023.html
- https://access.redhat.com/errata/RHSA-2026:20351
- https://access.redhat.com/errata/RHSA-2026:28212
- https://access.redhat.com/errata/RHSA-2026:28921
- https://access.redhat.com/errata/RHSA-2026:28973
- https://access.redhat.com/errata/RHSA-2026:29151
- https://access.redhat.com/errata/RHSA-2026:29874
- https://access.redhat.com/errata/RHSA-2026:33313
- https://access.redhat.com/errata/RHSA-2026:44481
- https://access.redhat.com/errata/RHSA-2026:58981
- https://access.redhat.com/security/cve/CVE-2026-9256
- https://bugzilla.redhat.com/show_bug.cgi?id=2480746
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-9256.json
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-9256",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-9256",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2026-05-22T00:00:00+00:00"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "f5sirt@f5.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.1,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.2
},
{
"type": "Secondary",
"source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.1,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.2
}
],
"cvssMetricV40": [
{
"type": "Secondary",
"source": "f5sirt@f5.com",
"cvssData": {
"Safety": "NOT_DEFINED",
"version": "4.0",
"Recovery": "NOT_DEFINED",
"baseScore": 9.2,
"Automatable": "NOT_DEFINED",
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"exploitMaturity": "NOT_DEFINED",
"providerUrgency": "NOT_DEFINED",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"attackRequirements": "PRESENT",
"privilegesRequired": "NONE",
"subIntegrityImpact": "NONE",
"vulnIntegrityImpact": "HIGH",
"integrityRequirement": "NOT_DEFINED",
"modifiedAttackVector": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"vulnAvailabilityImpact": "HIGH",
"availabilityRequirement": "NOT_DEFINED",
"modifiedUserInteraction": "NOT_DEFINED",
"modifiedAttackComplexity": "NOT_DEFINED",
"subConfidentialityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"confidentialityRequirement": "NOT_DEFINED",
"modifiedAttackRequirements": "NOT_DEFINED",
"modifiedPrivilegesRequired": "NOT_DEFINED",
"modifiedSubIntegrityImpact": "NOT_DEFINED",
"modifiedVulnIntegrityImpact": "NOT_DEFINED",
"vulnerabilityResponseEffort": "NOT_DEFINED",
"modifiedSubAvailabilityImpact": "NOT_DEFINED",
"modifiedVulnAvailabilityImpact": "NOT_DEFINED",
"modifiedSubConfidentialityImpact": "NOT_DEFINED",
"modifiedVulnConfidentialityImpact": "NOT_DEFINED"
}
}
]
},
"affected": [
{
"source": "f5sirt@f5.com",
"affectedData": [
{
"vendor": "F5",
"modules": [
"ngx_http_rewrite_module"
],
"product": "NGINX Plus",
"versions": [
{
"status": "affected",
"version": "37.0",
"lessThan": "37.0.1.1",
"versionType": "custom"
},
{
"status": "affected",
"version": "R36",
"lessThan": "R36 P5",
"versionType": "custom"
},
{
"status": "affected",
"version": "R32",
"lessThan": "R32 P7",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
},
{
"vendor": "F5",
"modules": [
"ngx_http_rewrite_module"
],
"product": "NGINX Open Source",
"versions": [
{
"status": "affected",
"version": "1.31.0",
"lessThan": "1.31.1",
"versionType": "custom"
},
{
"status": "affected",
"version": "1.30.0",
"lessThan": "1.30.2",
"versionType": "custom"
},
{
"status": "affected",
"version": "0.1.17",
"versionType": "custom",
"lessThanOrEqual": "0.9.7"
}
],
"defaultStatus": "unaffected"
}
]
},
{
"source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
"affectedData": [
{
"cpes": [
"cpe:/o:redhat:enterprise_linux:10.2"
],
"vendor": "Red Hat",
"product": "Red Hat Enterprise Linux 10",
"versions": [
{
"status": "unaffected",
"version": "2:1.26.3-6.el10_2.4",
"lessThan": "*",
"versionType": "rpm"
}
],
"packageName": "nginx",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:enterprise_linux:8"
],
"vendor": "Red Hat",
"product": "Red Hat Enterprise Linux 8",
"versions": [
{
"status": "unaffected",
"version": "8100020260611094050.489197e6",
"lessThan": "*",
"versionType": "rpm"
}
],
"packageName": "nginx:1.24",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:enterprise_linux:9"
],
"vendor": "Red Hat",
"product": "Red Hat Enterprise Linux 9",
"versions": [
{
"status": "unaffected",
"version": "9080020260610161820.9",
"lessThan": "*",
"versionType": "rpm"
}
],
"packageName": "nginx:1.24",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:enterprise_linux:9"
],
"vendor": "Red Hat",
"product": "Red Hat Enterprise Linux 9",
"versions": [
{
"status": "unaffected",
"version": "2:1.20.1-28.el9_8.3",
"lessThan": "*",
"versionType": "rpm"
}
],
"packageName": "nginx",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:enterprise_linux:9"
],
"vendor": "Red Hat",
"product": "Red Hat Enterprise Linux 9",
"versions": [
{
"status": "unaffected",
"version": "9080020260609152155.9",
"lessThan": "*",
"versionType": "rpm"
}
],
"packageName": "nginx:1.26",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:discovery:2::el9"
],
"vendor": "Red Hat",
"product": "Red Hat Discovery 2",
"versions": [
{
"status": "unaffected",
"version": "1782756541",
"lessThan": "*",
"versionType": "rpm"
}
],
"packageName": "discovery/discovery-ui-rhel9",
"collectionURL": "https://catalog.redhat.com/software/containers/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:hummingbird:1"
],
"vendor": "Red Hat",
"product": "Red Hat Hardened Images",
"versions": [
{
"status": "unaffected",
"version": "1.30.2-1.hum1",
"lessThan": "*",
"versionType": "rpm"
}
],
"packageName": "nginx-main",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:rhui:5::el9"
],
"vendor": "Red Hat",
"product": "Red Hat Update Infrastructure 5",
"versions": [
{
"status": "unaffected",
"version": "1784794818",
"lessThan": "*",
"versionType": "rpm"
}
],
"packageName": "rhui5/cds-kubernetes-rhel9",
"collectionURL": "https://catalog.redhat.com/software/containers/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:rhui:5::el9"
],
"vendor": "Red Hat",
"product": "Red Hat Update Infrastructure 5",
"versions": [
{
"status": "unaffected",
"version": "1784794778",
"lessThan": "*",
"versionType": "rpm"
}
],
"packageName": "rhui5/cds-rhel9",
"collectionURL": "https://catalog.redhat.com/software/containers/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:rhui:5::el9"
],
"vendor": "Red Hat",
"product": "Red Hat Update Infrastructure 5",
"versions": [
{
"status": "unaffected",
"version": "1784795076",
"lessThan": "*",
"versionType": "rpm"
}
],
"packageName": "rhui5/rhua-rhel9",
"collectionURL": "https://catalog.redhat.com/software/containers/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:rhui:5::el9"
],
"vendor": "Red Hat",
"product": "Red Hat Update Infrastructure 5",
"versions": [
{
"status": "unaffected",
"version": "1787241211",
"lessThan": "*",
"versionType": "rpm"
}
],
"packageName": "rhui5/cds-kubernetes-tp-rhel9",
"collectionURL": "https://catalog.redhat.com/software/containers/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:rhui:5::el9"
],
"vendor": "Red Hat",
"product": "Red Hat Update Infrastructure 5",
"versions": [
{
"status": "unaffected",
"version": "1787241260",
"lessThan": "*",
"versionType": "rpm"
}
],
"packageName": "rhui5/rhua-tp-rhel9",
"collectionURL": "https://catalog.redhat.com/software/containers/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:insights_proxy:1"
],
"vendor": "Red Hat",
"product": "Red Hat Lightspeed proxy 1",
"packageName": "insights-proxy/insights-proxy-container-rhel9",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "affected"
}
]
}
],
"published": "2026-05-22T15:16:27.073",
"references": [
{
"url": "https://my.f5.com/manage/s/article/K000161377",
"tags": [
"Mitigation",
"Vendor Advisory"
],
"source": "f5sirt@f5.com"
},
{
"url": "http://www.openwall.com/lists/oss-security/2026/05/22/14",
"tags": [
"Mailing List"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://lists.debian.org/debian-lts-announce/2026/06/msg00023.html",
"tags": [
"Mailing List",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://access.redhat.com/errata/RHSA-2026:20351",
"tags": [
"Third Party Advisory"
],
"source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
},
{
"url": "https://access.redhat.com/errata/RHSA-2026:28212",
"tags": [
"Third Party Advisory"
],
"source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
},
{
"url": "https://access.redhat.com/errata/RHSA-2026:28921",
"tags": [
"Third Party Advisory"
],
"source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
},
{
"url": "https://access.redhat.com/errata/RHSA-2026:28973",
"tags": [
"Third Party Advisory"
],
"source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
},
{
"url": "https://access.redhat.com/errata/RHSA-2026:29151",
"tags": [
"Third Party Advisory"
],
"source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
},
{
"url": "https://access.redhat.com/errata/RHSA-2026:29874",
"tags": [
"Third Party Advisory"
],
"source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
},
{
"url": "https://access.redhat.com/errata/RHSA-2026:33313",
"tags": [
"Third Party Advisory"
],
"source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
},
{
"url": "https://access.redhat.com/errata/RHSA-2026:44481",
"tags": [
"Third Party Advisory"
],
"source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
},
{
"url": "https://access.redhat.com/errata/RHSA-2026:58981",
"source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
},
{
"url": "https://access.redhat.com/security/cve/CVE-2026-9256",
"tags": [
"Third Party Advisory"
],
"source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
},
{
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2480746",
"tags": [
"Issue Tracking",
"Third Party Advisory"
],
"source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
},
{
"url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-9256.json",
"tags": [
"Third Party Advisory"
],
"source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "f5sirt@f5.com",
"description": [
{
"lang": "en",
"value": "CWE-122"
}
]
},
{
"type": "Secondary",
"source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
"description": [
{
"lang": "en",
"value": "CWE-122"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite directive uses a regex pattern with distinct, overlapping Perl-Compatible Regular Expression (PCRE) captures (for example, ^/((.*))$) and a replacement string that references multiple such captures (for example, $1$2) in a redirect or arguments context. An unauthenticated attacker along with conditions beyond their control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. \n\n\nNote: Software versions which have reached End of Technical Support (EoTS) are not evaluated."
},
{
"lang": "es",
"value": "NGINX Plus y NGINX Open Source tienen una vulnerabilidad en el módulo ngx_http_rewrite_module. Esta vulnerabilidad existe cuando una directiva de reescritura utiliza un patrón de expresión regular (regex) con capturas de expresiones regulares compatibles con Perl (PCRE) distintas y superpuestas (por ejemplo, ^/((.*))$) y una cadena de reemplazo que hace referencia a múltiples de dichas capturas (por ejemplo, $1$2) en un contexto de redirección o de argumentos. Un atacante no autenticado, junto con condiciones fuera de su control, puede explotar esta vulnerabilidad enviando solicitudes HTTP manipuladas. Esto puede causar un desbordamiento de búfer de pila en el proceso de trabajador de NGINX, lo que lleva a un reinicio. Además, los atacantes pueden ejecutar código en sistemas con la aleatorización del espacio de direcciones (ASLR) deshabilitada o cuando el atacante puede eludir ASLR.\n\nNota: Las versiones de software que han alcanzado el fin del soporte técnico (EoTS) no se evalúan."
}
],
"lastModified": "2026-08-25T13:19:33.400",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:f5:nginx_open_source:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "634D5CE2-039A-4D93-A03D-0FD7D0DEF686",
"versionEndIncluding": "0.9.7",
"versionStartIncluding": "0.1.17"
},
{
"criteria": "cpe:2.3:a:f5:nginx_open_source:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "07D3ADC7-5F8B-4709-B5D6-54C24904DC78",
"versionEndExcluding": "1.30.2",
"versionStartIncluding": "1.0.0"
},
{
"criteria": "cpe:2.3:a:f5:nginx_open_source:1.31.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A33B307E-A953-42D8-9ED6-975AA79C160F"
},
{
"criteria": "cpe:2.3:a:f5:nginx_plus:*:*:*:*:continuous_releases:*:*:*",
"vulnerable": true,
"matchCriteriaId": "277F91F7-F75B-463E-A342-4624E52ED3ED",
"versionEndExcluding": "r36",
"versionStartIncluding": "r33"
},
{
"criteria": "cpe:2.3:a:f5:nginx_plus:37.0.0.1:*:*:*:long-term_support:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5D03EB59-E885-4614-B19C-BD441B4A56EC"
},
{
"criteria": "cpe:2.3:a:f5:nginx_plus:r32:-:*:*:continuous_releases:*:*:*",
"vulnerable": true,
"matchCriteriaId": "773FBF7A-CCEE-4B2A-A265-7938640D1B79"
},
{
"criteria": "cpe:2.3:a:f5:nginx_plus:r32:p1:*:*:continuous_releases:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BEA2A3DC-1CD8-40CE-912F-6264314CFFA7"
},
{
"criteria": "cpe:2.3:a:f5:nginx_plus:r32:p2:*:*:continuous_releases:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6AF063B8-955E-44C5-9358-1A22C8187600"
},
{
"criteria": "cpe:2.3:a:f5:nginx_plus:r32:p3:*:*:continuous_releases:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6B18D42C-A43E-4918-98EE-6A827B83EE3B"
},
{
"criteria": "cpe:2.3:a:f5:nginx_plus:r32:p4:*:*:continuous_releases:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9F8CE762-4BA6-413F-A8D8-BD7147C25FBD"
},
{
"criteria": "cpe:2.3:a:f5:nginx_plus:r32:p5:*:*:continuous_releases:*:*:*",
"vulnerable": true,
"matchCriteriaId": "913BF7CA-FF4B-4BF5-83C4-ED2B92719A55"
},
{
"criteria": "cpe:2.3:a:f5:nginx_plus:r32:p6:*:*:continuous_releases:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EAEF93AB-9631-41AC-BFBC-A87F9162EC06"
},
{
"criteria": "cpe:2.3:a:f5:nginx_plus:r36:-:*:*:continuous_releases:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6FCF8770-25AF-4A07-916B-16F50357A44E"
},
{
"criteria": "cpe:2.3:a:f5:nginx_plus:r36:p1:*:*:continuous_releases:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D5C601A4-8DA6-443E-8284-6DCD34E4F3CB"
},
{
"criteria": "cpe:2.3:a:f5:nginx_plus:r36:p2:*:*:continuous_releases:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EB6684A4-3869-4C21-B87A-129C30C99C28"
},
{
"criteria": "cpe:2.3:a:f5:nginx_plus:r36:p3:*:*:continuous_releases:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B2AC5070-A6B7-440B-A45A-90E751FF103E"
},
{
"criteria": "cpe:2.3:a:f5:nginx_plus:r36:p4:*:*:continuous_releases:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D7907F59-BBCC-4B5B-8BBC-92C14BB804D2"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:f5:dos:*:*:*:*:*:nginx:*:*",
"vulnerable": true,
"matchCriteriaId": "0772572C-26F9-4FA4-B9E6-BA40ED59F569",
"versionEndIncluding": "4.7.0",
"versionStartIncluding": "4.3.0"
},
{
"criteria": "cpe:2.3:a:f5:dos:4.9.0:*:*:*:*:nginx:*:*",
"vulnerable": true,
"matchCriteriaId": "DACAC9CB-16D3-4F55-A466-70035779B387"
},
{
"criteria": "cpe:2.3:a:f5:nginx_gateway_fabric:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "15B7F1FD-0C49-460F-9CB8-23DA730EC4BE",
"versionEndIncluding": "1.6.2",
"versionStartIncluding": "1.3.0"
},
{
"criteria": "cpe:2.3:a:f5:nginx_gateway_fabric:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "886468BC-0507-4C08-AAB6-EDF75A027C7A",
"versionEndExcluding": "2.6.2",
"versionStartIncluding": "2.0.0"
},
{
"criteria": "cpe:2.3:a:f5:nginx_ingress_controller:*:*:*:*:continuous_releases:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E54B5C35-49D7-43F6-B57C-4606F75192CE",
"versionEndIncluding": "3.7.2",
"versionStartIncluding": "3.5.0"
},
{
"criteria": "cpe:2.3:a:f5:nginx_ingress_controller:*:*:*:*:continuous_releases:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DB6D172C-2716-40B9-B74C-D3029EDD171F",
"versionEndIncluding": "4.0.1",
"versionStartIncluding": "4.0.0"
},
{
"criteria": "cpe:2.3:a:f5:nginx_ingress_controller:*:*:*:*:continuous_releases:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AC40FB98-DFE4-4097-AEAE-A113C7DB4F1B",
"versionEndExcluding": "5.4.3",
"versionStartIncluding": "5.0.0"
},
{
"criteria": "cpe:2.3:a:f5:nginx_instance_manager:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B20E450F-5E56-452F-9C7C-12D65AF5D0ED",
"versionEndExcluding": "2.22.1",
"versionStartIncluding": "2.17.0"
},
{
"criteria": "cpe:2.3:a:f5:waf:*:*:*:*:*:nginx:*:*",
"vulnerable": true,
"matchCriteriaId": "EB1118B4-3EA7-4A69-8259-86BB8837FC00",
"versionEndIncluding": "4.16.0",
"versionStartIncluding": "4.10.0"
},
{
"criteria": "cpe:2.3:a:f5:waf:*:*:*:*:*:nginx:*:*",
"vulnerable": true,
"matchCriteriaId": "2DB79E6C-08B0-4341-BCBE-B8070DDAA7AF",
"versionEndIncluding": "5.8.0",
"versionStartIncluding": "5.2.0"
},
{
"criteria": "cpe:2.3:a:f5:waf:*:*:*:*:*:nginx:*:*",
"vulnerable": true,
"matchCriteriaId": "DEDD5520-0B29-4D54-8AD5-8C0B2935A733",
"versionEndIncluding": "5.13.0",
"versionStartIncluding": "5.9.0"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:redhat:discovery:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B5B1D946-5978-4818-BF21-A43D9C1365E1"
},
{
"criteria": "cpe:2.3:a:redhat:hardened_images:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "87DEB507-5B64-47D7-9A50-3B87FD1E571F"
},
{
"criteria": "cpe:2.3:a:redhat:update_infrastructure:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3FAF1DEF-A926-43D4-B94E-E7E02C813CD9",
"versionEndExcluding": "5.2",
"versionStartIncluding": "5.0"
},
{
"criteria": "cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FA6FEEC2-9F11-4643-8827-749718254FED"
},
{
"criteria": "cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F4CFF558-3C47-480D-A2F0-BABF26042943"
},
{
"criteria": "cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7F6FB57C-2BC7-487C-96DD-132683AEB35D"
},
{
"criteria": "cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D65C2163-CFC2-4ABB-8F4E-CB09CEBD006C"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "f5sirt@f5.com"
}