Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

NGNIX

NGNIXHTTP-сервер, обратный прокси сервер с поддержкой кеширования и балансировки нагрузки, TCP/UDP прокси-сервер, а также почтовый прокси-сервер.

Релизный цикл, информация об уязвимостях

Продукт: NGNIX
Вендор: f5

График релизов

1.241.251.261.271.281.2920232024202520262027

Недавние уязвимости NGNIX

Количество 138

debian логотип

CVE-2026-42945

3 месяца назад

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ ...

CVSS3: 8.1
EPSS: Средний
nvd логотип

CVE-2026-42945

3 месяца назад

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond its control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 8.1
EPSS: Средний
debian логотип

CVE-2026-42934

3 месяца назад

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ ...

CVSS3: 4.8
EPSS: Низкий
nvd логотип

CVE-2026-42934

3 месяца назад

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When charset, source_charset, and charset_map and proxy_pass with disabled buffering ("off") directives are configured, unauthenticated attackers can send requests that with conditions beyond the attackers' control to cause a heap buffer over-read in the NGINX worker process, leading to limited disclosure of memory or a restart.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 4.8
EPSS: Низкий
debian логотип

CVE-2026-42926

3 месяца назад

When NGINX Open Source is configured to proxy HTTP/2 traffic by settin ...

CVSS3: 5.8
EPSS: Низкий
nvd логотип

CVE-2026-42926

3 месяца назад

When NGINX Open Source is configured to proxy HTTP/2 traffic by setting proxy_http_version to 2, and also uses proxy_set_body, an attacker may be able to inject frame headers and payload bytes to the upstream peer.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 5.8
EPSS: Низкий
debian логотип

CVE-2026-40701

3 месяца назад

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ ...

CVSS3: 4.8
EPSS: Низкий
nvd логотип

CVE-2026-40701

3 месяца назад

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssl_module module when the ssl_verify_client directive is set to "on" or "optional," and the ssl_ocsp directive is set to "on" or the leaf parameters are configured with a resolver. With this configuration, an unauthenticated attacker can send requests along with conditions beyond its control that may cause a heap-use-after-free error in the NGINX worker process. This vulnerability may result in limited modification of data or the NGINX worker process restarting.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 4.8
EPSS: Низкий
debian логотип

CVE-2026-40460

3 месяца назад

When NGINX Plus or NGINX Open Source are configured to use the HTTP/3 ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-40460

3 месяца назад

When NGINX Plus or NGINX Open Source are configured to use the HTTP/3 QUIC module, an attacker may be able to spoof their source IP address allowing for bypass of authorization or bypass of rate limiting.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2026-42945

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ ...

CVSS3: 8.1
61%
Средний
3 месяца назад
nvd логотип
CVE-2026-42945

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond its control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 8.1
61%
Средний
3 месяца назад
debian логотип
CVE-2026-42934

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ ...

CVSS3: 4.8
1%
Низкий
3 месяца назад
nvd логотип
CVE-2026-42934

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When charset, source_charset, and charset_map and proxy_pass with disabled buffering ("off") directives are configured, unauthenticated attackers can send requests that with conditions beyond the attackers' control to cause a heap buffer over-read in the NGINX worker process, leading to limited disclosure of memory or a restart.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 4.8
1%
Низкий
3 месяца назад
debian логотип
CVE-2026-42926

When NGINX Open Source is configured to proxy HTTP/2 traffic by settin ...

CVSS3: 5.8
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-42926

When NGINX Open Source is configured to proxy HTTP/2 traffic by setting proxy_http_version to 2, and also uses proxy_set_body, an attacker may be able to inject frame headers and payload bytes to the upstream peer.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 5.8
0%
Низкий
3 месяца назад
debian логотип
CVE-2026-40701

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ ...

CVSS3: 4.8
1%
Низкий
3 месяца назад
nvd логотип
CVE-2026-40701

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssl_module module when the ssl_verify_client directive is set to "on" or "optional," and the ssl_ocsp directive is set to "on" or the leaf parameters are configured with a resolver. With this configuration, an unauthenticated attacker can send requests along with conditions beyond its control that may cause a heap-use-after-free error in the NGINX worker process. This vulnerability may result in limited modification of data or the NGINX worker process restarting.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 4.8
1%
Низкий
3 месяца назад
debian логотип
CVE-2026-40460

When NGINX Plus or NGINX Open Source are configured to use the HTTP/3 ...

CVSS3: 6.5
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-40460

When NGINX Plus or NGINX Open Source are configured to use the HTTP/3 QUIC module, an attacker may be able to spoof their source IP address allowing for bypass of authorization or bypass of rate limiting.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 6.5
0%
Низкий
3 месяца назад

Уязвимостей на страницу


Поделиться