Количество 12
Количество 12
BDU:2026-06961
Уязвимость модуля ngx_http_ssl_module веб-серверов NGINX Plus и NGINX Open Source, позволяющая нарушителю оказать воздействие на конфиденциальность и доступность защищаемой информации
ROS-20260626-73-0039
Уязвимость angie
ROS-20260609-73-0009
Уязвимость nginx
CVE-2026-40701
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssl_module module when the ssl_verify_client directive is set to "on" or "optional," and the ssl_ocsp directive is set to "on" or the leaf parameters are configured with a resolver. With this configuration, an unauthenticated attacker can send requests along with conditions beyond its control that may cause a heap-use-after-free error in the NGINX worker process. This vulnerability may result in limited modification of data or the NGINX worker process restarting. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CVE-2026-40701
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssl_module module when the ssl_verify_client directive is set to "on" or "optional," and the ssl_ocsp directive is set to "on" or the leaf parameters are configured with a resolver. With this configuration, an unauthenticated attacker can send requests along with conditions beyond its control that may cause a heap-use-after-free error in the NGINX worker process. This vulnerability may result in limited modification of data or the NGINX worker process restarting. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CVE-2026-40701
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssl_module module when the ssl_verify_client directive is set to "on" or "optional," and the ssl_ocsp directive is set to "on" or the leaf parameters are configured with a resolver. With this configuration, an unauthenticated attacker can send requests along with conditions beyond its control that may cause a heap-use-after-free error in the NGINX worker process. This vulnerability may result in limited modification of data or the NGINX worker process restarting. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CVE-2026-40701
NGINX ngx_http_ssl_module vulnerability
CVE-2026-40701
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ ...
GHSA-x88q-x2r7-vg3g
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssl_module module when the ssl_verify_client directive is set to "on" or "optional," and the ssl_ocsp directive is set to "on" or the leaf parameters are configured with a resolver. With this configuration, an unauthenticated attacker can send requests along with conditions beyond its control that may cause a heap-use-after-free error in the NGINX worker process. This vulnerability may result in limited modification of data or the NGINX worker process restarting. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
openSUSE-SU-2026:20796-1
Security update for nginx
SUSE-SU-2026:2050-1
Security update for nginx
SUSE-SU-2026:2370-1
Security update for nginx
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
BDU:2026-06961 Уязвимость модуля ngx_http_ssl_module веб-серверов NGINX Plus и NGINX Open Source, позволяющая нарушителю оказать воздействие на конфиденциальность и доступность защищаемой информации | CVSS3: 4.8 | 1% Низкий | 3 месяца назад | |
ROS-20260626-73-0039 Уязвимость angie | CVSS3: 4.8 | 1% Низкий | около 1 месяца назад | |
ROS-20260609-73-0009 Уязвимость nginx | CVSS3: 4.8 | 1% Низкий | около 2 месяцев назад | |
CVE-2026-40701 NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssl_module module when the ssl_verify_client directive is set to "on" or "optional," and the ssl_ocsp directive is set to "on" or the leaf parameters are configured with a resolver. With this configuration, an unauthenticated attacker can send requests along with conditions beyond its control that may cause a heap-use-after-free error in the NGINX worker process. This vulnerability may result in limited modification of data or the NGINX worker process restarting. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | CVSS3: 4.8 | 1% Низкий | 3 месяца назад | |
CVE-2026-40701 NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssl_module module when the ssl_verify_client directive is set to "on" or "optional," and the ssl_ocsp directive is set to "on" or the leaf parameters are configured with a resolver. With this configuration, an unauthenticated attacker can send requests along with conditions beyond its control that may cause a heap-use-after-free error in the NGINX worker process. This vulnerability may result in limited modification of data or the NGINX worker process restarting. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | CVSS3: 4.8 | 1% Низкий | 3 месяца назад | |
CVE-2026-40701 NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssl_module module when the ssl_verify_client directive is set to "on" or "optional," and the ssl_ocsp directive is set to "on" or the leaf parameters are configured with a resolver. With this configuration, an unauthenticated attacker can send requests along with conditions beyond its control that may cause a heap-use-after-free error in the NGINX worker process. This vulnerability may result in limited modification of data or the NGINX worker process restarting. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | CVSS3: 4.8 | 1% Низкий | 3 месяца назад | |
CVE-2026-40701 NGINX ngx_http_ssl_module vulnerability | CVSS3: 4.8 | 1% Низкий | 3 месяца назад | |
CVE-2026-40701 NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ ... | CVSS3: 4.8 | 1% Низкий | 3 месяца назад | |
GHSA-x88q-x2r7-vg3g NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssl_module module when the ssl_verify_client directive is set to "on" or "optional," and the ssl_ocsp directive is set to "on" or the leaf parameters are configured with a resolver. With this configuration, an unauthenticated attacker can send requests along with conditions beyond its control that may cause a heap-use-after-free error in the NGINX worker process. This vulnerability may result in limited modification of data or the NGINX worker process restarting. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | CVSS3: 4.8 | 1% Низкий | 3 месяца назад | |
openSUSE-SU-2026:20796-1 Security update for nginx | 2 месяца назад | |||
SUSE-SU-2026:2050-1 Security update for nginx | 2 месяца назад | |||
SUSE-SU-2026:2370-1 Security update for nginx | около 2 месяцев назад |
Уязвимостей на страницу