Skip to main content
Mallory
Unrated

NGINX Gateway Fabric NginxProxy CRD access log format configuration injection

IdentifiersCVE-2026-50107CWE-74

CVE-2026-50107 is a high-severity injection vulnerability in NGINX Gateway Fabric when NGINX Plus or NGINX Open Source is used as the data plane. The flaw is in the NGINX configuration generator component, which renders user-controlled string values from the NginxProxy Custom Resource Definition (CRD) access log format setting directly into generated NGINX configuration templates without sanitization or escaping. An authenticated attacker who can create or modify NginxProxy CRDs can supply crafted values that break out of the intended log-format context and inject arbitrary NGINX configuration directives into the generated configuration. The trigger is through the control plane configuration path; the vulnerability is not triggered directly via data plane traffic.

Share:
For your environment

Are you exposed to this one?

Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.

ANALYST BRIEF

Impact, mitigation & remediation

What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.

Impact

What an attacker gets, and what they’ve been doing with it.

Successful exploitation allows an authenticated attacker with CRD modification privileges to alter generated NGINX configuration by injecting arbitrary directives. Based on the provided content, this can expose sensitive data from the NGINX pod filesystem, proxy traffic to attacker-controlled endpoints, and cause denial of service by injecting configuration that prevents NGINX from reloading. More broadly, it enables unauthorized behavior and service instability within Kubernetes environments running NGINX Gateway Fabric.

Mitigation

If you can’t patch tonight, do this now.

If immediate patching is not possible, restrict the ability to create or modify NginxProxy CRDs to trusted administrators only, review and sanitize all configured access log format values in NginxProxy resources, and monitor for unexpected NGINX configuration changes or reload failures. Reducing exposure of the control plane and tightening Kubernetes RBAC around the affected CRDs are the primary mitigations based on the available information.

Remediation

Patch, then assume compromise.

Upgrade NGINX Gateway Fabric to a fixed release. The provided content states affected versions are 2.3.0 through 2.6.3 and that the issue is fixed in version 2.6.4. Also review existing NginxProxy CRD access log format values for unsafe content and ensure the configuration generator/templates sanitize or properly escape user-supplied input before rendering into NGINX configuration.
PUBLIC EXPLOITS

Exploits

No public exploits tracked yet. Mallory keeps watching.

VALID 0 / 0 TOTALView more in app

No public exploit code observed for this vulnerability.

EXPOSURE SURFACE

Affected products & vendors

Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.

VendorProductType
F5Nginxapplication
F5Nginx Gateway Fabricapplication
F5Nginx Plusapplication
NginxGateway Fabricapplication

Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets are affected, which adversaries are exploiting it right now, which detections to deploy, and what to do tonight.
Exposure mapping

Query your assets running an affected version, and investigate the blast radius.

Threat actor evidence

Every observed campaign linking this CVE to a named adversary.

Associated malware

Malware families riding this exploit, with evidence and IOCs.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Vendor-by-vendor mapping

Cross-references every affected SKU, including bundled OEM variants.

Social activity2

Community discussion across Reddit, Mastodon, and other social sources.