VYPR

Bitnami package

nginx-gateway-fabric

pkg:bitnami/nginx-gateway-fabric

Vulnerabilities (5)

  • CVE-2026-32682Jun 17, 2026
    affected >= 1.3.0, < 2.6.4fixed 2.6.4

    When NGINX Gateway Fabric is configured using GRPCRoutes, an authenticated, remote attacker with permission to create or modify GRPCRoute resources can cause the NGINX Gateway Fabric control plane to terminate by sending undisclosed GRPCRoute configurations containing backendRef

  • CVE-2026-50107Jun 17, 2026
    affected >= 2.3.0, < 2.6.4fixed 2.6.4

    When NGINX Plus or NGINX Open Source is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in the NGINX configuration generator component of NGINX Gateway Fabric. User-supplied string values from the NginxProxy Custom Resource Definition (CRD

  • CVE-2026-11311Jun 17, 2026
    affected >= 2.5.0, < 2.6.4fixed 2.6.4

    When NGINX Plus is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in the NGINX configuration generator component of NGINX Gateway Fabric. User-supplied string values from the NginxProxy Custom Resource Definition serverTokens field and th

  • CVE-2026-48142Jun 17, 2026
    affected >= 1.3.0, < 2.6.4fixed 2.6.4

    NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When content is served or proxied through a location block with both source_charset utf-8; and a charset directive (for example, charset koi8-r;) configured, remote, unauthenticated attac

  • CVE-2026-42055Jun 17, 2026
    affected >= 1.3.0, < 2.6.4fixed 2.6.4

    NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass directives are used to proxy HTTP/2 traffic, the ignore_invalid_headers directive is set