CVE-2026-60065

MEDIUM CVSS 4.0: 6.3 EPSS 0.45%
Updated Aug 10, 2026
F5
Parameter Value
CVSS 6.3 (MEDIUM)
Affected Versions 1.3.0 — r36
Fixed In 2.6.7
Type CWE-125 (Out-of-bounds Read)
Vendor F5
Public PoC No

When NGINX Plus is configured to use the Message Queuing Telemetry Transport (MQTT) filter module (ngx_stream_mqtt_filter_module), unauthenticated attackers can send requests with conditions beyond the attacker's control to cause a heap buffer over-read in the NGINX worker process, leading to a restart. Impact: This vulnerability may allow remote unauthenticated attackers to have limited control to restart the NGINX worker process. There is no control plane exposure; this is a data plane issue only.

Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Attack Requirements
Present
Additional conditions required
Privileges Required
None
No privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
None
No data leak
Integrity
None
No data modification
Availability
Low
Partial disruption

CVSS Vector v4.0

Weakness Type (CWE)

Vulnerable Products 19

Configuration From (including) Up to (excluding)
F5 Nginx_Gateway_Fabric
cpe:2.3:a:f5:nginx_gateway_fabric:*:*:*:*:*:*:*:*
1.3.0 <= 1.6.2
F5 Nginx_Gateway_Fabric
cpe:2.3:a:f5:nginx_gateway_fabric:*:*:*:*:*:*:*:*
2.0.0 2.6.7
F5 Nginx_Ingress_Controller
cpe:2.3:a:f5:nginx_ingress_controller:*:*:*:*:continuous_releases:*:*:*
3.5.0 <= 3.7.2
F5 Nginx_Ingress_Controller
cpe:2.3:a:f5:nginx_ingress_controller:*:*:*:*:continuous_releases:*:*:*
5.0.0 5.5.3
F5 Nginx_Ingress_Controller
cpe:2.3:a:f5:nginx_ingress_controller:*:*:*:*:long-term_support:*:*:*
2026-lts-r1 2026-lts-r4
F5 Nginx_Ingress_Controller
cpe:2.3:a:f5:nginx_ingress_controller:4.0.0:*:*:*:continuous_releases:*:*:*
— —
F5 Nginx_Ingress_Controller
cpe:2.3:a:f5:nginx_ingress_controller:4.0.1:*:*:*:continuous_releases:*:*:*
— —
F5 Nginx_Plus
cpe:2.3:a:f5:nginx_plus:*:*:*:*:*:*:*:*
37.0.0.1 37.0.3.1
F5 Nginx_Plus
cpe:2.3:a:f5:nginx_plus:*:*:*:*:*:*:*:*
r33 r36
F5 Nginx_Plus
cpe:2.3:a:f5:nginx_plus:r36:-:*:*:*:*:*:*
— —
F5 Nginx_Plus
cpe:2.3:a:f5:nginx_plus:r36:p1:*:*:*:*:*:*
— —
F5 Nginx_Plus
cpe:2.3:a:f5:nginx_plus:r36:p2:*:*:*:*:*:*
— —
F5 Nginx_Plus
cpe:2.3:a:f5:nginx_plus:r36:p3:*:*:*:*:*:*
— —
F5 Nginx_Plus
cpe:2.3:a:f5:nginx_plus:r36:p4:*:*:*:*:*:*
— —
F5 Nginx_Plus
cpe:2.3:a:f5:nginx_plus:r36:p5:*:*:*:*:*:*
— —
F5 Nginx_Plus
cpe:2.3:a:f5:nginx_plus:r36:p6:*:*:*:*:*:*
— —
F5 Waf
cpe:2.3:a:f5:waf:*:*:*:*:*:nginx:*:*
4.11.0 <= 4.16.0
F5 Waf
cpe:2.3:a:f5:waf:*:*:*:*:*:nginx:*:*
5.2.0 <= 5.8.0
F5 Waf
cpe:2.3:a:f5:waf:*:*:*:*:*:nginx:*:*
5.9.0 5.13.4