Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vh3x-jr27-wpwh

Опубликовано: 17 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 7.1
CVSS3: 6.5

Описание

When NGINX Gateway Fabric is configured using GRPCRoutes, an authenticated, remote attacker with permission to create or modify GRPCRoute resources can cause the NGINX Gateway Fabric control plane to terminate by sending undisclosed GRPCRoute configurations containing backendRef filters.

Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

When NGINX Gateway Fabric is configured using GRPCRoutes, an authenticated, remote attacker with permission to create or modify GRPCRoute resources can cause the NGINX Gateway Fabric control plane to terminate by sending undisclosed GRPCRoute configurations containing backendRef filters.

Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

EPSS

Процентиль: 22%
0.00292
Низкий

7.1 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-129

Связанные уязвимости

CVSS3: 6.5
nvd
около 2 месяцев назад

When NGINX Gateway Fabric is configured using GRPCRoutes, an authenticated, remote attacker with permission to create or modify GRPCRoute resources can cause the NGINX Gateway Fabric control plane to terminate by sending undisclosed GRPCRoute configurations containing backendRef filters. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 6.5
fstec
около 2 месяцев назад

Уязвимость функции маршрутизации gRPC-трафика GRPCRoute контроллера веб-сервера NGINX Gateway Fabric, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 22%
0.00292
Низкий

7.1 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-129