VDB
CVE-2026-9256
CVE-2026-9256
PUBLISHED
ea-nginx – version v1.31.0 ea-nginx-passenger – version v6.1.2 The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.
EPSS 0.24% · 46.9th percentile
Risk Scores
EPSS Score
0.24%
46.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| F5 | F5 DoS pour NGINX – version 4.9.0; | |
| ea-nginx-passenger | ea-nginx-passenger – version v6.1.2 | |
| NGINX | NGINX App Protect WAF – multiple versions | |
| NGINX | NGINX Ingress Controller – multiple versions | |
| NGINX | NGINX Plus – multiples versions; | |
| F5 | F5 WAF pour NGINX – de la version 5.9.0 à13.0; | |
| NGINX | NGINX App Protect WAF – multiples versions; | |
| F5 | F5 WAF for NGINX – versions 5.9.0 to 5.13.0 | |
| NGINX | NGINX Gateway Fabric – multiples versions; | |
| NGINX | NGINX Ingress Controller – multiples versions. | |
| NGINX | NGINX Instance Manager – versions 2.17.0 to 2.22.0 | |
| NGINX | NGINX Open Source – multiples versions; | |
| NGINX | NGINX Plus – multiple versions | |
| NGINX | NGINX Gateway Fabric – multiple versions | |
| NGINX | NGINX App Protect DoS – versions 4.3.0 to 4.7.0 | |
| NGINX | NGINX Open Source – multiple versions | |
| ea-nginx | ea-nginx – version v1.31.0 | |
| NGINX | NGINX Instance Manager – de la version 2.17.0 à22.0; | |
| F5 | F5 DoS for NGINX – version 4.9.0 | |
| NGINX | NGINX App Protect DoS – de la version 4.3.0 à7.0; |
Timeline
- May 22, 2026 PoC Published
- May 22, 2026 CVE Published
- May 22, 2026 PoC Published
- May 22, 2026 PoC Published
- May 22, 2026 PoC Published
- May 22, 2026 PoC Published
- May 22, 2026 PoC Published
- May 22, 2026 PoC Published
- May 22, 2026 PoC Published
- May 22, 2026 PoC Published
- May 23, 2026 EPSS Score
- May 23, 2026 CVE Updated
References
- https://cyber.gc.ca/en/alerts-advisories/f5-security-advisory-av26-501 advisory
- https://my.f5.com/manage/s/article/K000161377 vendor
- https://my.f5.com/manage/s/new-updated-articles#f-f5_document_type=Security%20Advisory vendor
- https://cyber.gc.ca/fr/alertes-avis/bulletin-securite-f5-av26-501 advisory
- https://cyber.gc.ca/en/alerts-advisories/cpanel-security-advisory-av26-508 advisory
- https://support.cpanel.net/hc/en-us/articles/40670279527831-Security-CVE-2026-9256-ea-nginx-v1-31-1-Security-Release-May-22-2026 vendor
- https://support.cpanel.net/hc/en-us/sections/360007088193-Security vendor
- Ingress NGINX Controller for Kubernetes Retires – Where to Go From Here third-party-analysis