CVE-2026-60065
Awaiting Analysis Awaiting Analysis - Queue

Heap Buffer Over-Read in NGINX Plus MQTT Filter Module

Vulnerability report for CVE-2026-60065, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-15

Last updated on: 2026-07-15

Assigner: F5 Networks

Description

When NGINX Plus is configured to use the Message Queuing Telemetry Transport (MQTT) filter module (ngx_stream_mqtt_filter_module), unauthenticated attackers can send requests with conditions beyond the attacker's control to cause a heap buffer over-read in the NGINX worker process, leading to a restart. Impact: This vulnerability may allow remote unauthenticated attackers to have limited control to restart the NGINX worker process. There is no control plane exposure; this is a data plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-15
Last Modified
2026-07-15
Generated
2026-08-04
AI Q&A
2026-07-15
EPSS Evaluated
2026-08-03
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
nginx nginx_plus *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-125 The product reads data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects NGINX Plus when configured with the MQTT filter module. Unauthenticated attackers can send specially crafted requests that cause a heap buffer over-read in the NGINX worker process, leading to an unexpected restart of the worker process.

Detection Guidance

Detecting this vulnerability requires monitoring NGINX Plus worker processes for unexpected restarts or crashes. Check NGINX logs for worker process termination events and inspect network traffic for unusual MQTT protocol anomalies. No specific commands are provided in the context.

Impact Analysis

This vulnerability allows remote unauthenticated attackers to cause NGINX worker processes to restart. This may lead to temporary service disruptions or degraded performance for users relying on NGINX Plus services.

Compliance Impact

This vulnerability does not directly impact compliance with GDPR or HIPAA as it only allows unauthenticated attackers to restart the NGINX worker process without exposing the control plane or accessing sensitive data. However, repeated worker process restarts could lead to service disruptions, potentially affecting availability requirements in compliance frameworks.

Mitigation Strategies

Disable the MQTT filter module (ngx_stream_mqtt_filter_module) in NGINX Plus configuration. Update NGINX Plus to the latest patched version if available. Restrict network access to NGINX Plus instances to trusted sources only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-60065. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart