Back

MEDIUM

NGINX Plus ngx_stream_mqtt_filter_module vulnerability

Published Jul 15, 2026

Description

When NGINX Plus is configured to use the Message Queuing Telemetry Transport (MQTT) filter module (ngx_stream_mqtt_filter_module), unauthenticated attackers can send requests with conditions beyond the attacker's control to cause a heap buffer over-read in the NGINX worker process, leading to a restart.

Impact: This vulnerability may allow remote unauthenticated attackers to have limited control to restart the NGINX worker process. There is no control plane exposure; this is a data plane issue only.

Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected products

Remediation

No remediation recorded yet.

References (2)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner f5
Published Jul 15, 2026
Updated Jul 15, 2026
Reserved Jul 8, 2026

CISA Vulnrichment

Updated Jul 15, 2026

NVD

Status Analyzed
Modified Aug 10, 2026

Red Hat

No data

ENISA EUVD

Assigner f5
Published Jul 15, 2026
Updated Jul 15, 2026

GitHub

No data