6.5
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L
Description
A vulnerability exists in the ngx_http_scgi_module and ngx_http_uwsgi_module modules that may result in excessive memory allocation or an over-read of data. When scgi_pass or uwsgi_pass is configured, an unauthenticated attacker with man-in-the-middle (MITM) ability to control responses from an upstream server may be able to read the memory of the NGINX worker process or restart it. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Basic Information
ID
CVE-2026-42946
Source
f5
Published
May 13, 2026 at 14:12
Affected Product
Vendor
F5
Product
NGINX Plus
Version
R37
Affected Versions
F5 NGINX Plus R36
F5 NGINX Plus R32
F5 NGINX Open Source 0.8.42
F5 NGINX Plus R32
F5 NGINX Open Source 0.8.42