Impact
An injection flaw in the configuration generator of NGINX Gateway Fabric allows an authenticated user with write permissions on Authentication Filter Custom Resource Definitions or their referenced secrets to supply unsanitized strings that are directly rendered into NGINX configuration templates. This flaw enables the attacker to inject arbitrary NGINX configuration directives, modifying the control plane behavior without affecting the data plane. The vulnerability is limited to the configuration layer and does not expose data plane traffic.
Affected Systems
The flaw affects F5’s NGINX Gateway Fabric when NGINX Plus is deployed as the data plane. All current releases that include the unpatched configuration generator are vulnerable until a patch or version upgrade is applied.
Risk and Exploitability
With a CVSS score of 8.6, the vulnerability is classified as high severity. The exploit requires authenticated access to the Kubernetes API with write privileges on the relevant CRDs, a common role within an organization’s internal environment. EPSS data is unavailable, and the flaw is not listed in CISA’s KEV catalog, but its potential impact remains significant for any actor who can obtain the necessary RBAC permissions.
OpenCVE Enrichment