Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

fstec логотип

BDU:2026-09927

Опубликовано: 15 июл. 2026
Источник: fstec
CVSS3: 8.1
CVSS2: 7.6
EPSS Низкий

Описание

Уязвимость директивы map HTTP-сервера NGINX Plus и NGINX Open Source связана с переполнением буфера в динамической памяти. Эксплуатация уязвимости может позволить нарушителю, действующему удаленно, выполнить произвольный код или вызвать отказ в обслуживании путем отправки специально сформированного HTTP-запроса

Вендор

NGINX Inc.
ООО «1С-Битрикс»

Наименование ПО

NGINX Gateway Fabric
NGINX Ingress Controller
NGINX App Protect WAF
NGINX Plus
NGINX Open Source
NGINX Instance Manager
F5 WAF for NGINX
bx-nginx

Версия ПО

от 1.3.0 до 1.6.2 включительно (NGINX Gateway Fabric)
от 4.0.0 до 4.0.1 включительно (NGINX Ingress Controller)
от 3.5.0 до 3.7.2 включительно (NGINX Ingress Controller)
от 5.2.0 до 5.8.0 включительно (NGINX App Protect WAF)
от 37.0.0.1 до 37.0.3.1 (NGINX Plus)
от R33 до R36 P7 (NGINX Plus)
от 1.31.2 до 1.31.3 (NGINX Open Source)
от 1.30.0 до 1.30.4 (NGINX Open Source)
от 2.17.0 до 2.22.1 включительно (NGINX Instance Manager)
от 5.9.0 до 5.13.3 включительно (F5 WAF for NGINX)
от 4.11.0 до 4.16.0 включительно (NGINX App Protect WAF)
от 2.0.0 до 2.6.7 (NGINX Gateway Fabric)
от 2026-lts-r1 до 2026-lts-r4 (NGINX Ingress Controller)
от 5.0.0 до 5.5.3 (NGINX Ingress Controller)
до 1.30.4 (bx-nginx)

Тип ПО

Прикладное ПО информационных систем
Сетевое программное средство
Программное средство защиты
Сетевое средство

Операционные системы и аппаратные платформы

-

Уровень опасности уязвимости

Высокий уровень опасности (базовая оценка CVSS 2.0 составляет 7,6)
Высокий уровень опасности (базовая оценка CVSS 3.1 составляет 8,1)
Критический уровень опасности (оценка CVSS 4.0 составляет 9,2)

Возможные меры по устранению уязвимости

Использование рекомендаций производителя:
https://my.f5.com/manage/s/article/K000162097
Для пакета bx-nginx:
Обновление пакета bx-nginx до версии 1.30.4 и выше

Статус уязвимости

Подтверждена производителем

Наличие эксплойта

Существует в открытом доступе

Информация об устранении

Уязвимость устранена

Идентификаторы других систем описаний уязвимостей

EPSS

Процентиль: 88%
0.03596
Низкий

8.1 High

CVSS3

7.6 High

CVSS2

Связанные уязвимости

CVSS3: 8.1
ubuntu
15 дней назад

A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the map's regex capture variables before referencing the map output variable. Alternatively, the same result could be achieved by using a non-cacheable variable in a string expression under certain conditions. An unauthenticated attacker along with conditions beyond their control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Impact: This vulnerability may allow remote attackers to cause a denial-of-service (DoS) on the NGINX system or to possibly trigger a code execution. There is no control plane exposure; this is a data plane issue only. Note: Software versions which have reached End of Technical Su...

CVSS3: 7
redhat
15 дней назад

A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the map's regex capture variables before referencing the map output variable. Alternatively, the same result could be achieved by using a non-cacheable variable in a string expression under certain conditions. An unauthenticated attacker along with conditions beyond their control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Impact: This vulnerability may allow remote attackers to cause a denial-of-service (DoS) on the NGINX system or to possibly trigger a code execution. There is no control plane exposure; this is a data plane issue only.  Note: Software versions which have reached End of Technical ...

CVSS3: 8.1
nvd
15 дней назад

A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the map's regex capture variables before referencing the map output variable. Alternatively, the same result could be achieved by using a non-cacheable variable in a string expression under certain conditions. An unauthenticated attacker along with conditions beyond their control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Impact: This vulnerability may allow remote attackers to cause a denial-of-service (DoS) on the NGINX system or to possibly trigger a code execution. There is no control plane exposure; this is a data plane issue only.  Note: Software versions which have reached End of Technica

CVSS3: 8.1
msrc
12 дней назад

NGINX Map directive and Regex matching vulnerability

CVSS3: 8.1
debian
15 дней назад

A vulnerability exists in NGINX Plus and NGINX Open Source when a mapd ...

EPSS

Процентиль: 88%
0.03596
Низкий

8.1 High

CVSS3

7.6 High

CVSS2