Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 19

Количество 19

ubuntu логотип

CVE-2026-60005

2 месяца назад

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module. When the slice directive and unnamed regex captures are configured or when a background cache update happens, unauthenticated attackers can send requests that may cause uninitialized memory access in the NGINX worker process, leading to limited disclosure of memory or a restart. Impact: This vulnerability may allow remote, unauthenticated attackers to have limited control to disclose memory contents or restart the NGINX worker process. There is no control plane exposure; this is a data plane issue only. Note: The ngx_http_slice_module module is not enabled by default; it's enabled with the --with-http_slice_module configuration parameter. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 8.2
EPSS: Низкий
redhat логотип

CVE-2026-60005

2 месяца назад

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module. When the slice directive and unnamed regex captures are configured or when a background cache update happens, unauthenticated attackers can send requests that may cause uninitialized memory access in the NGINX worker process, leading to limited disclosure of memory or a restart. Impact: This vulnerability may allow remote, unauthenticated attackers to have limited control to disclose memory contents or restart the NGINX worker process. There is no control plane exposure; this is a data plane issue only. Note: The ngx_http_slice_module module is not enabled by default; it's enabled with the --with-http_slice_module configuration parameter. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 8.2
EPSS: Низкий
nvd логотип

CVE-2026-60005

2 месяца назад

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module. When the slice directive and unnamed regex captures are configured or when a background cache update happens, unauthenticated attackers can send requests that may cause uninitialized memory access in the NGINX worker process, leading to limited disclosure of memory or a restart. Impact: This vulnerability may allow remote, unauthenticated attackers to have limited control to disclose memory contents or restart the NGINX worker process. There is no control plane exposure; this is a data plane issue only. Note: The ngx_http_slice_module module is not enabled by default; it's enabled with the --with-http_slice_module configuration parameter. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 8.2
EPSS: Низкий
msrc логотип

CVE-2026-60005

около 2 месяцев назад

NGINX ngx_http_slice_module vulnerability

EPSS: Низкий
debian логотип

CVE-2026-60005

2 месяца назад

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ ...

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-vxcv-h5wj-jxr5

2 месяца назад

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module. When the slice directive and unnamed regex captures are configured or when a background cache update happens, unauthenticated attackers can send requests that may cause uninitialized memory access in the NGINX worker process, leading to limited disclosure of memory or a restart. Impact: This vulnerability may allow remote, unauthenticated attackers to have limited control to disclose memory contents or restart the NGINX worker process. There is no control plane exposure; this is a data plane issue only. Note: The ngx_http_slice_module module is not enabled by default; it's enabled with the --with-http_slice_module configuration parameter. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 8.2
EPSS: Низкий
fstec логотип

BDU:2026-10487

2 месяца назад

Уязвимость модуля ngx_http_slice_module HTTP-сервера NGINX Plus и NGINX Open Source, позволяющая нарушителю раскрыть защищаемую информацию или вызвать отказ в обслуживании

CVSS3: 8.2
EPSS: Низкий
redos логотип

ROS-20260803-80-0009

около 1 месяца назад

Уязвимость nginx

CVSS3: 8.2
EPSS: Низкий
redos логотип

ROS-20260803-73-0010

около 1 месяца назад

Уязвимость nginx

CVSS3: 8.2
EPSS: Низкий
rocky логотип

RLSA-2026:59496

19 дней назад

Important: nginx:1.26 security update

EPSS: Низкий
rocky логотип

RLSA-2026:59490

19 дней назад

Important: nginx:1.24 security update

EPSS: Низкий
rocky логотип

RLSA-2026:59362

19 дней назад

Important: nginx security update

EPSS: Низкий
rocky логотип

RLSA-2026:59220

20 дней назад

Important: nginx security update

EPSS: Низкий
rocky логотип

RLSA-2026:59216

20 дней назад

Important: nginx:1.24 security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-59496

20 дней назад

ELSA-2026-59496: nginx:1.26 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-59490

14 дней назад

ELSA-2026-59490: nginx:1.24 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-59362

18 дней назад

ELSA-2026-59362: nginx security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-59220

20 дней назад

ELSA-2026-59220: nginx security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-59216

20 дней назад

ELSA-2026-59216: nginx:1.24 security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-60005

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module. When the slice directive and unnamed regex captures are configured or when a background cache update happens, unauthenticated attackers can send requests that may cause uninitialized memory access in the NGINX worker process, leading to limited disclosure of memory or a restart. Impact: This vulnerability may allow remote, unauthenticated attackers to have limited control to disclose memory contents or restart the NGINX worker process. There is no control plane exposure; this is a data plane issue only. Note: The ngx_http_slice_module module is not enabled by default; it's enabled with the --with-http_slice_module configuration parameter. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 8.2
1%
Низкий
2 месяца назад
redhat логотип
CVE-2026-60005

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module. When the slice directive and unnamed regex captures are configured or when a background cache update happens, unauthenticated attackers can send requests that may cause uninitialized memory access in the NGINX worker process, leading to limited disclosure of memory or a restart. Impact: This vulnerability may allow remote, unauthenticated attackers to have limited control to disclose memory contents or restart the NGINX worker process. There is no control plane exposure; this is a data plane issue only. Note: The ngx_http_slice_module module is not enabled by default; it's enabled with the --with-http_slice_module configuration parameter. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 8.2
1%
Низкий
2 месяца назад
nvd логотип
CVE-2026-60005

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module. When the slice directive and unnamed regex captures are configured or when a background cache update happens, unauthenticated attackers can send requests that may cause uninitialized memory access in the NGINX worker process, leading to limited disclosure of memory or a restart. Impact: This vulnerability may allow remote, unauthenticated attackers to have limited control to disclose memory contents or restart the NGINX worker process. There is no control plane exposure; this is a data plane issue only. Note: The ngx_http_slice_module module is not enabled by default; it's enabled with the --with-http_slice_module configuration parameter. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 8.2
1%
Низкий
2 месяца назад
msrc логотип
CVE-2026-60005

NGINX ngx_http_slice_module vulnerability

1%
Низкий
около 2 месяцев назад
debian логотип
CVE-2026-60005

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ ...

CVSS3: 8.2
1%
Низкий
2 месяца назад
github логотип
GHSA-vxcv-h5wj-jxr5

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module. When the slice directive and unnamed regex captures are configured or when a background cache update happens, unauthenticated attackers can send requests that may cause uninitialized memory access in the NGINX worker process, leading to limited disclosure of memory or a restart. Impact: This vulnerability may allow remote, unauthenticated attackers to have limited control to disclose memory contents or restart the NGINX worker process. There is no control plane exposure; this is a data plane issue only. Note: The ngx_http_slice_module module is not enabled by default; it's enabled with the --with-http_slice_module configuration parameter. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 8.2
1%
Низкий
2 месяца назад
fstec логотип
BDU:2026-10487

Уязвимость модуля ngx_http_slice_module HTTP-сервера NGINX Plus и NGINX Open Source, позволяющая нарушителю раскрыть защищаемую информацию или вызвать отказ в обслуживании

CVSS3: 8.2
1%
Низкий
2 месяца назад
redos логотип
ROS-20260803-80-0009

Уязвимость nginx

CVSS3: 8.2
1%
Низкий
около 1 месяца назад
redos логотип
ROS-20260803-73-0010

Уязвимость nginx

CVSS3: 8.2
1%
Низкий
около 1 месяца назад
rocky логотип
RLSA-2026:59496

Important: nginx:1.26 security update

19 дней назад
rocky логотип
RLSA-2026:59490

Important: nginx:1.24 security update

19 дней назад
rocky логотип
RLSA-2026:59362

Important: nginx security update

19 дней назад
rocky логотип
RLSA-2026:59220

Important: nginx security update

20 дней назад
rocky логотип
RLSA-2026:59216

Important: nginx:1.24 security update

20 дней назад
oracle-oval логотип
ELSA-2026-59496

ELSA-2026-59496: nginx:1.26 security update (IMPORTANT)

20 дней назад
oracle-oval логотип
ELSA-2026-59490

ELSA-2026-59490: nginx:1.24 security update (IMPORTANT)

14 дней назад
oracle-oval логотип
ELSA-2026-59362

ELSA-2026-59362: nginx security update (IMPORTANT)

18 дней назад
oracle-oval логотип
ELSA-2026-59220

ELSA-2026-59220: nginx security update (IMPORTANT)

20 дней назад
oracle-oval логотип
ELSA-2026-59216

ELSA-2026-59216: nginx:1.24 security update (IMPORTANT)

20 дней назад

Уязвимостей на страницу

exploitDog - Комплексное решение для обнаружения, оценки и устранения уязвимостей.