F5 Product Security Update Advisory

F5 Product Security Update Advisory
  • F5 has released a security update to address vulnerabilities discovered in its NGINX products.
  • The affected vulnerabilities are CVE-2026-42533 and CVE-2026-60005.
  • CVE-2026-42533 is a heap-based buffer overflow vulnerability that occurs during the processing of regular expressions in NGINX’s map directive.
  • CVE-2026-60005 is an uninitialized memory access vulnerability occurring in NGINX’s ngxhttpslice_module.
  • Affected products include NGINX Plus, NGINX Open Source, NGINX Instance Manager, F5 WAF for NGINX, NGINX App Protect WAF, NGINX Gateway Fabric, NGINX Ingress Controller, and NGINX Ingress Controller 2026 LTS.
  • F5 has advised users to update to the latest version of the Vulnerability Patch for each product.
  • The patched versions are NGINX Plus 37.0.3.1, NGINX Plus R36 P7, NGINX Open Source 1.30.4, NGINX Open Source 1.31.3, NGINX Instance Manager 2.22.2, F5 WAF for NGINX 5.13.4, NGINX Gateway Fabric 2.6.7, NGINX Ingress Controller 5.5.3, And NGINX Ingress Controller 2026 LTS 2026-lts-r4.