Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

fstec логотип

BDU:2026-10487

Опубликовано: 15 июл. 2026
Источник: fstec
CVSS3: 8.2
CVSS2: 8.5
EPSS Низкий

Описание

Уязвимость модуля ngx_http_slice_module HTTP-сервера NGINX Plus и NGINX Open Source связана с использованием неинициализированного ресурса. Эксплуатация уязвимости может позволить нарушителю, действующему удаленно, раскрыть защищаемую информацию или вызвать отказ в обслуживании

Вендор

NGINX Inc.
ООО «1С-Битрикс»

Наименование ПО

NGINX Gateway Fabric
NGINX Ingress Controller
NGINX App Protect WAF
NGINX Plus
NGINX Open Source
NGINX Instance Manager
F5 WAF for NGINX
bx-nginx

Версия ПО

от 1.3.0 до 1.6.2 включительно (NGINX Gateway Fabric)
от 4.0.0 до 4.0.1 включительно (NGINX Ingress Controller)
от 3.5.0 до 3.7.2 включительно (NGINX Ingress Controller)
от 5.2.0 до 5.8.0 включительно (NGINX App Protect WAF)
от 37.0.0.1 до 37.0.3.1 (NGINX Plus)
от R33 до R36 P7 (NGINX Plus)
от 1.31.2 до 1.31.3 (NGINX Open Source)
от 1.30.0 до 1.30.4 (NGINX Open Source)
от 2.17.0 до 2.22.1 включительно (NGINX Instance Manager)
от 5.9.0 до 5.13.3 включительно (F5 WAF for NGINX)
от 4.11.0 до 4.16.0 включительно (NGINX App Protect WAF)
от 2.0.0 до 2.6.7 (NGINX Gateway Fabric)
от 2026-lts-r1 до 2026-lts-r4 (NGINX Ingress Controller)
от 5.0.0 до 5.5.3 (NGINX Ingress Controller)
до 1.30.4 (bx-nginx)

Тип ПО

Прикладное ПО информационных систем
Сетевое программное средство
Программное средство защиты
Сетевое средство

Операционные системы и аппаратные платформы

-

Уровень опасности уязвимости

Высокий уровень опасности (базовая оценка CVSS 2.0 составляет 8,5)
Высокий уровень опасности (базовая оценка CVSS 3.1 составляет 8,2)
Высокий уровень опасности (оценка CVSS 4.0 составляет 8,8)

Возможные меры по устранению уязвимости

Использование рекомендаций производителя:
https://my.f5.com/manage/s/article/K000162100
Для пакета bx-nginx:
Обновление пакета bx-nginx до версии 1.30.4 и выше

Статус уязвимости

Подтверждена производителем

Наличие эксплойта

Данные уточняются

Информация об устранении

Уязвимость устранена

Идентификаторы других систем описаний уязвимостей

EPSS

Процентиль: 45%
0.0061
Низкий

8.2 High

CVSS3

8.5 High

CVSS2

Связанные уязвимости

CVSS3: 8.2
ubuntu
15 дней назад

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module. When the slice directive and unnamed regex captures are configured or when a background cache update happens, unauthenticated attackers can send requests that may cause uninitialized memory access in the NGINX worker process, leading to limited disclosure of memory or a restart. Impact: This vulnerability may allow remote, unauthenticated attackers to have limited control to disclose memory contents or restart the NGINX worker process. There is no control plane exposure; this is a data plane issue only. Note: The ngx_http_slice_module module is not enabled by default; it's enabled with the --with-http_slice_module configuration parameter. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 8.2
redhat
15 дней назад

A vulnerability in the NGINX ngx_http_slice_module allows remote, unauthenticated attackers to access uninitialized memory via crafted requests. If configured with unnamed regex captures or background cache updates, this flaw can result in limited memory disclosure or a denial-of-service crash.

CVSS3: 8.2
nvd
15 дней назад

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module. When the slice directive and unnamed regex captures are configured or when a background cache update happens, unauthenticated attackers can send requests that may cause uninitialized memory access in the NGINX worker process, leading to limited disclosure of memory or a restart. Impact: This vulnerability may allow remote, unauthenticated attackers to have limited control to disclose memory contents or restart the NGINX worker process. There is no control plane exposure; this is a data plane issue only. Note: The ngx_http_slice_module module is not enabled by default; it's enabled with the --with-http_slice_module configuration parameter. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

msrc
12 дней назад

NGINX ngx_http_slice_module vulnerability

CVSS3: 8.2
debian
15 дней назад

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ ...

EPSS

Процентиль: 45%
0.0061
Низкий

8.2 High

CVSS3

8.5 High

CVSS2