[GH-ISSUE #5281] NGINX vulnerability CVE-2026-1642 #3155

Open
opened 2026-02-26 07:37:58 +03:00 by kerem · 1 comment
Owner

Originally created by @flostyen on GitHub (Feb 6, 2026).
Original GitHub issue: https://github.com/NginxProxyManager/nginx-proxy-manager/issues/5281

Checklist

  • Have you pulled and found the error with jc21/nginx-proxy-manager:latest docker image?
    • Yes
  • Are you sure you're not using someone else's docker image?
    • Yes
  • Have you searched for similar issues (both open and closed)?
    • Yes

Describe the bug

NGINX vulnerability CVE-2026-1642

https://my.f5.com/manage/s/article/K000159824

A vulnerability exists in NGINX OSS and NGINX Plus when configured to proxy to upstream Transport Layer Security (TLS) servers. An attacker with a man-in-the-middle (MITM) position on the upstream server side—along with conditions beyond the attacker's control—may be able to inject plain text data into the response from an upstream proxied server. (CVE-2026-1642)

Nginx Fixed versions:
1.29.5
1.28.2

Nginx Proxy Manager Version
2.13.7

Originally created by @flostyen on GitHub (Feb 6, 2026). Original GitHub issue: https://github.com/NginxProxyManager/nginx-proxy-manager/issues/5281 **Checklist** - Have you pulled and found the error with `jc21/nginx-proxy-manager:latest` docker image? - Yes - Are you sure you're not using someone else's docker image? - Yes - Have you searched for similar issues (both open and closed)? - Yes **Describe the bug** NGINX vulnerability CVE-2026-1642 https://my.f5.com/manage/s/article/K000159824 A vulnerability exists in NGINX OSS and NGINX Plus when configured to proxy to upstream Transport Layer Security (TLS) servers. An attacker with a man-in-the-middle (MITM) position on the upstream server side—along with conditions beyond the attacker's control—may be able to inject plain text data into the response from an upstream proxied server. ([CVE-2026-1642](https://www.cve.org/CVERecord?id=CVE-2026-1642)) Nginx Fixed versions: 1.29.5 1.28.2 **Nginx Proxy Manager Version** 2.13.7
Author
Owner

@jc21 commented on GitHub (Feb 17, 2026):

NPM uses Openresty, so until they fix it there, I can't fix it here.

https://github.com/openresty/openresty/issues/1099

<!-- gh-comment-id:3917325550 --> @jc21 commented on GitHub (Feb 17, 2026): NPM uses Openresty, so until they fix it there, I can't fix it here. https://github.com/openresty/openresty/issues/1099
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
starred/nginx-proxy-manager-NginxProxyManager#3155
No description provided.