f5
15 known vulnerabilities affecting f5 products.
Products
nginx_gateway_fabric 8
nginx_ingress_controller 8
nginx_plus 8
waf 8
nginx_instance_manager 6
nginx_open_source 5
dos 4
big-ip_policy_enforcement_manager 3
big-ip_ssl_orchestrator 3
big-ip_webaccelerator 3
big-ip_websafe 3
big-ip_access_policy_manager 3
big-ip_advanced_firewall_manager 3
big-ip_advanced_web_application_firewall 3
big-ip_analytics 3
big-ip_application_acceleration_manager 3
big-ip_application_security_manager 3
big-ip_application_visibility_and_reporting 3
big-ip_carrier-grade_nat 3
big-ip_ddos_hybrid_defender 3
big-ip_domain_name_system 3
big-ip_fraud_protection_service 3
big-ip_global_traffic_manager 3
big-ip_link_controller 3
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2021-40438 | Act now | 100.0% | 9.0 | ● | A crafted request uri-path can cause mod_proxy to forward the request to an orig… |
| CVE-2023-44487 | Act now | 100.0% | 7.5 | ● | The HTTP/2 protocol allows a denial of service (server resource consumption) bec… |
| CVE-2026-42945 | High | 68.0% | 8.1 | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_mo… | |
| CVE-2026-9256 | Medium | 10.9% | 8.1 | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_mo… | |
| CVE-2026-8711 | Medium | 9.7% | 8.1 | NGINX JavaScript has a vulnerability when the js_fetch_proxy directive is config… | |
| CVE-2026-42055 | Medium | 6.5% | 8.1 | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_m… | |
| CVE-2026-42533 | Medium | 4.5% | 8.1 | A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive … | |
| CVE-2026-60005 | Medium | 0.7% | 8.2 | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_modu… | |
| CVE-2026-59762 | Medium | 0.6% | 7.5 | When an HTTP/2 profile is configured on a virtual server, undisclosed requests c… | |
| CVE-2026-39458 | Medium | 0.3% | 7.5 | When a BIG-IP is configured with DNS caching (Such as a DNS profile with cachin… | |
| CVE-2026-48142 | Low | 0.7% | 4.8 | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_mo… | |
| CVE-2026-56434 | Low | 0.5% | 6.5 | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssi_module… | |
| CVE-2026-60062 | Low | 0.3% | 6.4 | The NGINX Agent config_dirs directive allows a low-privileged attacker to gain l… | |
| CVE-2026-60065 | Low | 0.3% | 3.7 | When NGINX Plus is configured to use the Message Queuing Telemetry Transport (MQ… | |
| CVE-2026-63020 | Low | 0.2% | 3.1 | A vulnerability exists in an undisclosed BIG-IP Configuration utility page that … |