← All vendors

f5

15 known vulnerabilities affecting f5 products.

Products

nginx_gateway_fabric 8 nginx_ingress_controller 8 nginx_plus 8 waf 8 nginx_instance_manager 6 nginx_open_source 5 dos 4 big-ip_policy_enforcement_manager 3 big-ip_ssl_orchestrator 3 big-ip_webaccelerator 3 big-ip_websafe 3 big-ip_access_policy_manager 3 big-ip_advanced_firewall_manager 3 big-ip_advanced_web_application_firewall 3 big-ip_analytics 3 big-ip_application_acceleration_manager 3 big-ip_application_security_manager 3 big-ip_application_visibility_and_reporting 3 big-ip_carrier-grade_nat 3 big-ip_ddos_hybrid_defender 3 big-ip_domain_name_system 3 big-ip_fraud_protection_service 3 big-ip_global_traffic_manager 3 big-ip_link_controller 3

Vulnerabilities by priority

CVEPriorityEPSSCVSSKEVWhat
CVE-2021-40438 Act now 100.0% 9.0 A crafted request uri-path can cause mod_proxy to forward the request to an orig…
CVE-2023-44487 Act now 100.0% 7.5 The HTTP/2 protocol allows a denial of service (server resource consumption) bec…
CVE-2026-42945 High 68.0% 8.1 NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_mo…
CVE-2026-9256 Medium 10.9% 8.1 NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_mo…
CVE-2026-8711 Medium 9.7% 8.1 NGINX JavaScript has a vulnerability when the js_fetch_proxy directive is config…
CVE-2026-42055 Medium 6.5% 8.1 NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_m…
CVE-2026-42533 Medium 4.5% 8.1 A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive …
CVE-2026-60005 Medium 0.7% 8.2 NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_modu…
CVE-2026-59762 Medium 0.6% 7.5 When an HTTP/2 profile is configured on a virtual server, undisclosed requests c…
CVE-2026-39458 Medium 0.3% 7.5 When a BIG-IP is configured with DNS caching (Such as a DNS profile with cachin…
CVE-2026-48142 Low 0.7% 4.8 NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_mo…
CVE-2026-56434 Low 0.5% 6.5 NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssi_module…
CVE-2026-60062 Low 0.3% 6.4 The NGINX Agent config_dirs directive allows a low-privileged attacker to gain l…
CVE-2026-60065 Low 0.3% 3.7 When NGINX Plus is configured to use the Message Queuing Telemetry Transport (MQ…
CVE-2026-63020 Low 0.2% 3.1 A vulnerability exists in an undisclosed BIG-IP Configuration utility page that …