Acceptance of Extraneous Untrusted Data With Trusted Data Affecting nginx package, versions [1.3.0,1.28.2)[1.29.0,1.29.5)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of Concept
EPSS
0.35% (29th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-NGINX-15204454
  • published4 Feb 2026
  • disclosed4 Feb 2026
  • creditUnknown

Introduced: 4 Feb 2026

CVE-2026-1642  (opens in a new tab)
CWE-349  (opens in a new tab)

How to fix?

Upgrade nginx to version 1.28.2, 1.29.5 or higher.

Overview

Affected versions of this package are vulnerable to Acceptance of Extraneous Untrusted Data With Trusted Data via the HTTP/2 modules (grpc and proxy_v2). An attacker can inject unauthorized plain text data into responses from an upstream server by performing a man-in-the-middle attack on the upstream server side, under certain conditions beyond the attacker's control.

CVSS Base Scores

version 4.0
version 3.1