以下是对该漏洞描述和影响的中文翻译: 描述: 当 NGINX Plus 被配置为 NGINX Gateway Fabric 的数据平面时,NGINX Gateway Fabric 的 NGINX 配置生成器组件中存在注入漏洞。来自认证过滤器(Authentication Filter)自定义资源定义中 或 字段,或认证过滤器所引用的 Secret 中 字段的用户提供的字符串值,会被直接渲染到 NGINX 配置模板中,且未进行净化或转义。 影响: 拥有创建或修改这些资源权限的已认证攻击者,可以构造特定的值,从而注入任
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| F5 | NGINX Gateway Fabric | 2.5.0 ~ 2.6.8 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-66842 | 8.8 HIGH | BIG-IP and BIG-IQ Configuration utility vulnerability |
| CVE-2026-77180 | 8.3 HIGH | NGINX Ingress Controller vulnerability |
| CVE-2026-18329 | 8.2 HIGH | NGINX ngx_http_js_module vulnerability |
| CVE-2026-78689 | 8.1 HIGH | NGINX ngx_http_js_module vulnerablility |
| CVE-2026-78222 | 7.5 HIGH | NGINX ngx_http_js_module vulnerability |
| CVE-2026-63020 | 3.1 LOW | BIG-IP Configuration utility vulnerability |
No comments yet