Description
When NGINX Plus is configured to use the Message Queuing Telemetry Transport (MQTT) filter module (ngx_stream_mqtt_filter_module), unauthenticated attackers can send requests with conditions beyond the attacker's control to cause a heap buffer over-read in the NGINX worker process, leading to a restart.

Impact:
This vulnerability may allow remote unauthenticated attackers to have limited control to restart the NGINX worker process. There is no control plane exposure; this is a data plane issue only.

Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Published: 2026-07-15
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a heap buffer over‑read in the NGINX worker process caused by the ngx_stream_mqtt_filter_module when it receives MQTT packets that exceed normal size bounds. This over‑read triggers an internal failure that results in a restart of the worker process. No evidence suggests data or configuration disclosure; the attack only causes temporary data plane disruption by bringing the affected process down.

Affected Systems

F5 distributed system products that embed NGINX Plus and enable the ngx_stream_mqtt_filter_module. Specific build numbers are not listed, and end‑of‑technical‑support versions are not considered. The vulnerability affects only the data plane; the control plane remains untouched.

Risk and Exploitability

The CVSS v3.1 score of 6.3 indicates moderate severity. The EPSS score is below 1 %, implying a low likelihood of exploitation at present. This CVE is not listed in CISA’s Known Exploited Vulnerabilities catalog. The description indicates that an attacker requires only remote, unauthenticated access to the MQTT service port, suggesting the attack vector is remote network access to NGINX Plus instances with the module enabled.

Generated by OpenCVE AI on July 31, 2026 at 03:33 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to the latest F5 NGINX Plus release that includes the patch for the MQTT filter module bug.
  • If the MQTT functionality is unnecessary, disable or remove the ngx_stream_mqtt_filter_module configuration to eliminate the attack surface.
  • Restrict inbound traffic to the MQTT service by allowing only trusted IP ranges and using network segmentation to reduce exposure to the NGINX Plus instances.

Generated by OpenCVE AI on July 31, 2026 at 03:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared F5
F5 nginx Plus
Vendors & Products F5
F5 nginx Plus

Wed, 15 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 15 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Description When NGINX Plus is configured to use the Message Queuing Telemetry Transport (MQTT) filter module (ngx_stream_mqtt_filter_module), unauthenticated attackers can send requests with conditions beyond the attacker's control to cause a heap buffer over-read in the NGINX worker process, leading to a restart. Impact: This vulnerability may allow remote unauthenticated attackers to have limited control to restart the NGINX worker process. There is no control plane exposure; this is a data plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Title NGINX Plus ngx_stream_mqtt_filter_module vulnerability
Weaknesses CWE-125
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L'}

cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: f5

Published:

Updated: 2026-07-15T15:39:17.208Z

Reserved: 2026-07-08T15:49:43.065Z

Link: CVE-2026-60065

cve-icon Vulnrichment

Updated: 2026-07-15T15:39:01.422Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T03:45:04Z

Weaknesses