Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 11

Количество 11

fstec логотип

BDU:2026-08934

около 1 месяца назад

Уязвимость модуля ngx_http_charset_module веб-серверов NGINX Plus и NGINX Open Source, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации или вызвать отказ в обслуживании

CVSS3: 4.8
EPSS: Низкий
redos логотип

ROS-20260714-73-0061

17 дней назад

Уязвимость nginx

CVSS3: 4.8
EPSS: Низкий
redos логотип

ROS-20260714-73-0060

17 дней назад

Уязвимость angie

CVSS3: 4.8
EPSS: Низкий
ubuntu логотип

CVE-2026-48142

около 1 месяца назад

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When content is served or proxied through a location block with both source_charset utf-8; and a charset directive (for example, charset koi8-r;) configured, remote, unauthenticated attackers can send requests (in conjunction with conditions beyond their control) to cause a heap buffer over-read in the NGINX worker process, leading to limited disclosure of memory or a restart. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 4.8
EPSS: Низкий
redhat логотип

CVE-2026-48142

около 1 месяца назад

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When content is served or proxied through a location block with both source_charset utf-8; and a charset directive (for example, charset koi8-r;) configured, remote, unauthenticated attackers can send requests (in conjunction with conditions beyond their control) to cause a heap buffer over-read in the NGINX worker process, leading to limited disclosure of memory or a restart. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 4.8
EPSS: Низкий
nvd логотип

CVE-2026-48142

около 1 месяца назад

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When content is served or proxied through a location block with both source_charset utf-8; and a charset directive (for example, charset koi8-r;) configured, remote, unauthenticated attackers can send requests (in conjunction with conditions beyond their control) to cause a heap buffer over-read in the NGINX worker process, leading to limited disclosure of memory or a restart. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 4.8
EPSS: Низкий
msrc логотип

CVE-2026-48142

около 1 месяца назад

NGINX ngx_http_charset_module vulnerability

CVSS3: 4.8
EPSS: Низкий
debian логотип

CVE-2026-48142

около 1 месяца назад

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ ...

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-2388-jp8v-fg9w

около 1 месяца назад

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When content is served or proxied through a location block with both source_charset utf-8; and a charset directive (for example, charset koi8-r;) configured, remote, unauthenticated attackers can send requests (in conjunction with conditions beyond their control) to cause a heap buffer over-read in the NGINX worker process, leading to limited disclosure of memory or a restart. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 4.8
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3329-1

3 дня назад

Security update for nginx

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21439-1

7 дней назад

Security update for nginx

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2026-08934

Уязвимость модуля ngx_http_charset_module веб-серверов NGINX Plus и NGINX Open Source, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации или вызвать отказ в обслуживании

CVSS3: 4.8
1%
Низкий
около 1 месяца назад
redos логотип
ROS-20260714-73-0061

Уязвимость nginx

CVSS3: 4.8
1%
Низкий
17 дней назад
redos логотип
ROS-20260714-73-0060

Уязвимость angie

CVSS3: 4.8
1%
Низкий
17 дней назад
ubuntu логотип
CVE-2026-48142

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When content is served or proxied through a location block with both source_charset utf-8; and a charset directive (for example, charset koi8-r;) configured, remote, unauthenticated attackers can send requests (in conjunction with conditions beyond their control) to cause a heap buffer over-read in the NGINX worker process, leading to limited disclosure of memory or a restart. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 4.8
1%
Низкий
около 1 месяца назад
redhat логотип
CVE-2026-48142

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When content is served or proxied through a location block with both source_charset utf-8; and a charset directive (for example, charset koi8-r;) configured, remote, unauthenticated attackers can send requests (in conjunction with conditions beyond their control) to cause a heap buffer over-read in the NGINX worker process, leading to limited disclosure of memory or a restart. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 4.8
1%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-48142

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When content is served or proxied through a location block with both source_charset utf-8; and a charset directive (for example, charset koi8-r;) configured, remote, unauthenticated attackers can send requests (in conjunction with conditions beyond their control) to cause a heap buffer over-read in the NGINX worker process, leading to limited disclosure of memory or a restart. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 4.8
1%
Низкий
около 1 месяца назад
msrc логотип
CVE-2026-48142

NGINX ngx_http_charset_module vulnerability

CVSS3: 4.8
1%
Низкий
около 1 месяца назад
debian логотип
CVE-2026-48142

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ ...

CVSS3: 4.8
1%
Низкий
около 1 месяца назад
github логотип
GHSA-2388-jp8v-fg9w

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When content is served or proxied through a location block with both source_charset utf-8; and a charset directive (for example, charset koi8-r;) configured, remote, unauthenticated attackers can send requests (in conjunction with conditions beyond their control) to cause a heap buffer over-read in the NGINX worker process, leading to limited disclosure of memory or a restart. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 4.8
1%
Низкий
около 1 месяца назад
suse-cvrf логотип
SUSE-SU-2026:3329-1

Security update for nginx

3 дня назад
suse-cvrf логотип
openSUSE-SU-2026:21439-1

Security update for nginx

7 дней назад

Уязвимостей на страницу