Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

fstec логотип

BDU:2026-08881

Опубликовано: 17 июн. 2026
Источник: fstec
CVSS3: 8.1
CVSS2: 7.6
EPSS Низкий

Описание

Уязвимость модулей ngx_http_proxy_v2_module и ngx_http_grpc_module веб-серверов NGINX Plus и NGINX Open Source связана с выходом операции за границы буфера в памяти. Эксплуатация уязвимости может позволить нарушителю, действующему удаленно, выполнить произвольный код или вызвать отказ в обслуживании

Вендор

NGINX Inc.
ООО "Веб-Сервер"
ООО «1С-Битрикс»

Наименование ПО

NGINX Plus
NGINX App Protect DoS
NGINX Gateway Fabric
NGINX Ingress Controller
NGINX Instance Manager
NGINX App Protect WAF
F5 DoS for NGINX
NGINX Open Source
F5 WAF for NGINX
Angie
Angie PRO
bx-nginx

Версия ПО

от R33 до R36 включительно (NGINX Plus)
от 4.3.0 до 4.7.0 включительно (NGINX App Protect DoS)
от 1.3.0 до 1.6.2 включительно (NGINX Gateway Fabric)
от 4.0.0 до 4.0.1 включительно (NGINX Ingress Controller)
от 3.5.0 до 3.7.2 включительно (NGINX Ingress Controller)
от 2.17.0 до 2.22.0 включительно (NGINX Instance Manager)
от 5.2.0 до 5.8.0 включительно (NGINX App Protect WAF)
от 4.10.0 до 4.16.0 включительно (NGINX App Protect WAF)
4.9.0 (F5 DoS for NGINX)
от 37.0.0 до 37.0.1 включительно (NGINX Plus)
от 1.30.0 до 1.30.2 включительно (NGINX Open Source)
1.31.1 (NGINX Open Source)
от 5.9.0 до 5.13.1 включительно (F5 WAF for NGINX)
от 2.0.0 до 2.6.3 включительно (NGINX Gateway Fabric)
от 5.0.0 до 5.5.0 включительно (NGINX Ingress Controller)
до 1.11.8 (Angie)
до 1.11.8 (Angie PRO)
до 1.30.4 (bx-nginx)

Тип ПО

Сетевое средство
Программное средство защиты
Прикладное ПО информационных систем
Сетевое программное средство

Операционные системы и аппаратные платформы

-

Уровень опасности уязвимости

Высокий уровень опасности (базовая оценка CVSS 2.0 составляет 7,6)
Высокий уровень опасности (базовая оценка CVSS 3.1 составляет 8,1)
Критический уровень опасности (оценка CVSS 4.0 составляет 9,2)

Возможные меры по устранению уязвимости

Использование рекомендаций:
https://my.f5.com/manage/s/article/K000161584
Для Angie:
https://angie.software/news/releases/angie-1-11-8/
Для пакета bx-nginx:
Обновление пакета bx-nginx до версии 1.30.4 и выше
Компенсирующие меры:
В случае невозможности установки обновлений выполните одно или оба из следующих действий:
- удалите директиву ignore_invalid_headers off из конфигурации:
- уменьшите размер директивы large_client_header_buffers до размера меньше 2 мегабайт.

Статус уязвимости

Подтверждена производителем

Наличие эксплойта

Данные уточняются

Информация об устранении

Уязвимость устранена

Идентификаторы других систем описаний уязвимостей

EPSS

Процентиль: 88%
0.03552
Низкий

8.1 High

CVSS3

7.6 High

CVSS2

Связанные уязвимости

CVSS3: 8.1
redos
17 дней назад

Уязвимость angie

CVSS3: 8.1
ubuntu
около 1 месяца назад

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass directives are used to proxy HTTP/2 traffic, the ignore_invalid_headers directive is set to off, and the large_client_header_buffers directive size is larger than 2 megabytes. A remote, unauthenticated attacker, along with conditions beyond their control, could send large headers while creating an upstream request. This may cause a heap-based buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 8.1
redhat
около 1 месяца назад

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass directives are used to proxy HTTP/2 traffic, the ignore_invalid_headers directive is set to off, and the large_client_header_buffers directive size is larger than 2 megabytes. A remote, unauthenticated attacker, along with conditions beyond their control, could send large headers while creating an upstream request. This may cause a heap-based buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 8.1
nvd
около 1 месяца назад

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass directives are used to proxy HTTP/2 traffic, the ignore_invalid_headers directive is set to off, and the large_client_header_buffers directive size is larger than 2 megabytes. A remote, unauthenticated attacker, along with conditions beyond their control, could send large headers while creating an upstream request. This may cause a heap-based buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 8.1
msrc
30 дней назад

NGINX ngx_http_proxy_v2_module and ngx_http_grpc_module vulnerability

EPSS

Процентиль: 88%
0.03552
Низкий

8.1 High

CVSS3

7.6 High

CVSS2