Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

fstec логотип

BDU:2026-10487

Опубликовано: 15 июл. 2026
Источник: fstec
CVSS3: 8.2
CVSS2: 8.5
EPSS Низкий

Описание

Уязвимость модуля ngx_http_slice_module HTTP-сервера NGINX Plus и NGINX Open Source связана с использованием неинициализированного ресурса. Эксплуатация уязвимости может позволить нарушителю, действующему удаленно, раскрыть защищаемую информацию или вызвать отказ в обслуживании

Вендор

Сообщество свободного программного обеспечения
Red Hat, Inc.
ООО «Ред Софт»
Canonical Ltd.
АО «ИВК»
NGINX Inc.
ООО «1С-Битрикс»
АО «СберТех»

Наименование ПО

Debian GNU/Linux
Red Hat Enterprise Linux
РЕД ОС
Ubuntu
АЛЬТ СП 10
Red Hat Hardened Images
NGINX Gateway Fabric
NGINX Ingress Controller
NGINX App Protect WAF
NGINX Plus
NGINX Open Source
NGINX Instance Manager
F5 WAF for NGINX
bx-nginx
Platform V SynGX

Версия ПО

9 (Debian GNU/Linux)
8 (Red Hat Enterprise Linux)
10 (Debian GNU/Linux)
11 (Debian GNU/Linux)
12 (Debian GNU/Linux)
7.3 (РЕД ОС)
22.04 LTS (Ubuntu)
9 (Red Hat Enterprise Linux)
- (АЛЬТ СП 10)
24.04 LTS (Ubuntu)
10 (Red Hat Enterprise Linux)
13 (Debian GNU/Linux)
8.0 (РЕД ОС)
- (Red Hat Hardened Images)
26.04 LTS (Ubuntu)
от 1.3.0 до 1.6.2 включительно (NGINX Gateway Fabric)
от 4.0.0 до 4.0.1 включительно (NGINX Ingress Controller)
от 3.5.0 до 3.7.2 включительно (NGINX Ingress Controller)
от 5.2.0 до 5.8.0 включительно (NGINX App Protect WAF)
от 37.0.0.1 до 37.0.3.1 (NGINX Plus)
от R33 до R36 P7 (NGINX Plus)
от 1.31.2 до 1.31.3 (NGINX Open Source)
от 1.30.0 до 1.30.4 (NGINX Open Source)
от 2.17.0 до 2.22.1 включительно (NGINX Instance Manager)
от 5.9.0 до 5.13.3 включительно (F5 WAF for NGINX)
от 4.11.0 до 4.16.0 включительно (NGINX App Protect WAF)
от 2.0.0 до 2.6.7 (NGINX Gateway Fabric)
от 2026-lts-r1 до 2026-lts-r4 (NGINX Ingress Controller)
от 5.0.0 до 5.5.3 (NGINX Ingress Controller)
до 1.30.4 (bx-nginx)
3.2.0-fstec (Platform V SynGX)

Тип ПО

Операционная система
Прикладное ПО информационных систем
Сетевое программное средство
Программное средство защиты
Сетевое средство

Операционные системы и аппаратные платформы

Сообщество свободного программного обеспечения Debian GNU/Linux 9
Red Hat, Inc. Red Hat Enterprise Linux 8
Сообщество свободного программного обеспечения Debian GNU/Linux 10
Сообщество свободного программного обеспечения Debian GNU/Linux 11
Сообщество свободного программного обеспечения Debian GNU/Linux 12
ООО «Ред Софт» РЕД ОС 7.3
Canonical Ltd. Ubuntu 22.04 LTS
Red Hat, Inc. Red Hat Enterprise Linux 9
АО «ИВК» АЛЬТ СП 10 -
Canonical Ltd. Ubuntu 24.04 LTS
Red Hat, Inc. Red Hat Enterprise Linux 10
Сообщество свободного программного обеспечения Debian GNU/Linux 13
ООО «Ред Софт» РЕД ОС 8.0
Canonical Ltd. Ubuntu 26.04 LTS

Уровень опасности уязвимости

Высокий уровень опасности (базовая оценка CVSS 2.0 составляет 8,5)
Высокий уровень опасности (базовая оценка CVSS 3.1 составляет 8,2)
Высокий уровень опасности (оценка CVSS 4.0 составляет 8,8)

Возможные меры по устранению уязвимости

В условиях отсутствия обновлений безопасности от производителя рекомендуется придерживаться "Рекомендаций по безопасной настройке операционных систем LINUX", изложенных в методическом документе ФСТЭК России, утверждённом 25 декабря 2022 года.
Использование рекомендаций производителя:
Для пакета bx-nginx:
Обновление пакета bx-nginx до версии 1.30.4 и выше
Для ОС АЛЬТ СП 10: установка обновления из публичного репозитория программного средства:
https://altsp.su/obnovleniya-bezopasnosti/
Для Platform V SynGX:
Обновление Platform V SynGX до версии 3.2.1-fstec
Для Ред ОС:
http://repo.red-soft.ru/redos/7.3c/x86_64/updates/
http://repo.red-soft.ru/redos/8.0/x86_64/updates/
Для Debian GNU/Linux:
https://security-tracker.debian.org/tracker/CVE-2026-60005
https://deb.freexian.com/extended-lts/tracker/CVE-2026-60005
Для программных продуктов Red Hat Inc.:
https://access.redhat.com/security/cve/CVE-2026-60005
Для Ubuntu:
https://ubuntu.com/security/CVE-2026-60005

Статус уязвимости

Подтверждена производителем

Наличие эксплойта

Данные уточняются

Информация об устранении

Уязвимость устранена

Идентификаторы других систем описаний уязвимостей

EPSS

Процентиль: 52%
0.0071
Низкий

8.2 High

CVSS3

8.5 High

CVSS2

Связанные уязвимости

CVSS3: 8.2
redos
около 1 месяца назад

Уязвимость nginx

CVSS3: 8.2
redos
около 1 месяца назад

Уязвимость nginx

CVSS3: 8.2
ubuntu
2 месяца назад

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module. When the slice directive and unnamed regex captures are configured or when a background cache update happens, unauthenticated attackers can send requests that may cause uninitialized memory access in the NGINX worker process, leading to limited disclosure of memory or a restart. Impact: This vulnerability may allow remote, unauthenticated attackers to have limited control to disclose memory contents or restart the NGINX worker process. There is no control plane exposure; this is a data plane issue only. Note: The ngx_http_slice_module module is not enabled by default; it's enabled with the --with-http_slice_module configuration parameter. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 8.2
redhat
2 месяца назад

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module. When the slice directive and unnamed regex captures are configured or when a background cache update happens, unauthenticated attackers can send requests that may cause uninitialized memory access in the NGINX worker process, leading to limited disclosure of memory or a restart. Impact: This vulnerability may allow remote, unauthenticated attackers to have limited control to disclose memory contents or restart the NGINX worker process. There is no control plane exposure; this is a data plane issue only. Note: The ngx_http_slice_module module is not enabled by default; it's enabled with the --with-http_slice_module configuration parameter. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 8.2
nvd
2 месяца назад

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module. When the slice directive and unnamed regex captures are configured or when a background cache update happens, unauthenticated attackers can send requests that may cause uninitialized memory access in the NGINX worker process, leading to limited disclosure of memory or a restart. Impact: This vulnerability may allow remote, unauthenticated attackers to have limited control to disclose memory contents or restart the NGINX worker process. There is no control plane exposure; this is a data plane issue only. Note: The ngx_http_slice_module module is not enabled by default; it's enabled with the --with-http_slice_module configuration parameter. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

EPSS

Процентиль: 52%
0.0071
Низкий

8.2 High

CVSS3

8.5 High

CVSS2