CVE-2026-32682Medium· 6.5▾ SunlitWhen NGINX Gateway Fabric is configured using GRPCRoutes, an authenticated, remote attacker with permission to create or modify GRPCRoute resources can cause the NGINX Gateway Fabric control plane to terminate by sending undisclosed GRPC…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
When NGINX Gateway Fabric is configured using GRPCRoutes, an authenticated, remote attacker with permission to create or modify GRPCRoute resources can cause the NGINX Gateway Fabric control plane to terminate by sending undisclosed GRPCRoute configurations containing backendRef filters.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nginx_gateway_fabric >= 1.3.0, <= 1.6.2nginx_gateway_fabric >= 2.0.0, < 2.6.4Upgrade past the affected range:
nginx_gateway_fabric 2.6.4Connected by shared product, vendor, weakness, or advisory.
CVE-2026-42530High· 8.1NGINX Open Source has a vulnerability in the ngx_http_v3_module module
CVE-2026-11311High· 8.1When NGINX Plus is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in the NGINX configuration generator component of NGINX Gateway Fabric
CVE-2023-2008High· 8.2A flaw was found in the Linux kernel's udmabuf device driver, within a fault handler
CVE-2026-94127Critical· 9.8When a BIG-IP APM access policy and an OAuth profile is configured on a virtual server, specific malicious traffic can lead to Remote Code Execution (RCE). Impact: This vulnerability allows an unauthenticated attacker to perform remote …
CVE-2026-63020Low· 3.1A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages Impact: An attacker may trick authenticated BIG-IP users into accessing malicious links and reflect a …
CVE-2026-90439Medium· 6.5NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_v3_module module