{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3anginxgateway_fabric/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:nginx:gateway_fabric:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-66362"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["NGINX Gateway Fabric"],"_cs_severities":["medium"],"_cs_tags":["vulnerability","kubernetes","ingress","injection"],"_cs_type":"advisory","_cs_vendors":["NGINX"],"content_html":"\u003cp\u003eCVE-2026-66362 describes an injection vulnerability within the NGINX Gateway Fabric, specifically affecting the configuration generator component. When NGINX Plus is utilized as the data plane, user-supplied strings provided in the 'clientID' or 'cookieName' fields of an Authentication Filter Custom Resource Definition (CRD), or the 'clientSecret' field within a referenced Secret, are not properly sanitized or escaped. These values are rendered directly into NGINX configuration templates. An authenticated attacker who possesses the necessary Kubernetes role-based access control (RBAC) permissions to create or modify these specific resource types can inject arbitrary NGINX directives. This issue is strictly contained within the control plane, allowing for configuration-level manipulation rather than direct data plane exposure.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an authenticated attacker to manipulate the NGINX control plane. This could lead to a denial of service, modification of request routing, or unauthorized bypasses of authentication logic, depending on the specific directives injected. The vulnerability is scoped to environments where NGINX Gateway Fabric is deployed with NGINX Plus as the data plane, impacting users of the Kubernetes-native ingress infrastructure.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAudit Kubernetes RBAC policies to restrict who can create or modify Authentication Filter CRDs and associated Secrets.\u003c/li\u003e\n\u003cli\u003ePrioritize monitoring and validation of Kubernetes resource changes associated with NGINX Gateway Fabric.\u003c/li\u003e\n\u003cli\u003eReview the official NGINX security advisory for this CVE to confirm patch availability and upgrade instructions for NGINX Gateway Fabric.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-02T17:15:14Z","date_published":"2026-09-02T17:15:14Z","id":"https://feed.craftedsignal.io/briefs/2026-09-nginx-gateway-fabric-injection/","summary":"An injection vulnerability in the NGINX Gateway Fabric configuration generator allows authenticated users to inject arbitrary NGINX directives into the configuration when using NGINX Plus as the data plane.","title":"CVE-2026-66362: Injection Vulnerability in NGINX Gateway Fabric","url":"https://feed.craftedsignal.io/briefs/2026-09-nginx-gateway-fabric-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:nginx:gateway_fabric:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}