Количество 21
Количество 21
GHSA-h78r-86c6-jgp4
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite directive uses a regex pattern with distinct, overlapping Perl-Compatible Regular Expression (PCRE) captures (for example, ^/((.*))$) and a replacement string that references multiple such captures (for example, $1$2) in a redirect or arguments context. An unauthenticated attacker along with conditions beyond their control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CVE-2026-9256
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite directive uses a regex pattern with distinct, overlapping Perl-Compatible Regular Expression (PCRE) captures (for example, ^/((.*))$) and a replacement string that references multiple such captures (for example, $1$2) in a redirect or arguments context. An unauthenticated attacker along with conditions beyond their control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CVE-2026-9256
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite directive uses a regex pattern with distinct, overlapping Perl-Compatible Regular Expression (PCRE) captures (for example, ^/((.*))$) and a replacement string that references multiple such captures (for example, $1$2) in a redirect or arguments context. An unauthenticated attacker along with conditions beyond their control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CVE-2026-9256
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite directive uses a regex pattern with distinct, overlapping Perl-Compatible Regular Expression (PCRE) captures (for example, ^/((.*))$) and a replacement string that references multiple such captures (for example, $1$2) in a redirect or arguments context. An unauthenticated attacker along with conditions beyond their control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CVE-2026-9256
NGINX ngx_http_rewrite_module vulnerability
CVE-2026-9256
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ ...
openSUSE-SU-2026:21107-1
Security update for nginx
SUSE-SU-2026:2307-1
Security update for nginx
RLSA-2026:29874
Important: nginx security update
RLSA-2026:29151
Important: nginx:1.26 security update
RLSA-2026:28921
Important: nginx:1.24 security update
RLSA-2026:28212
Important: nginx:1.24 security update
ELSA-2026-29874
ELSA-2026-29874: nginx security update (IMPORTANT)
ELSA-2026-29151
ELSA-2026-29151: nginx:1.26 security update (IMPORTANT)
ELSA-2026-28973
ELSA-2026-28973: nginx security update (IMPORTANT)
ELSA-2026-28921
ELSA-2026-28921: nginx:1.24 security update (IMPORTANT)
ELSA-2026-28212
ELSA-2026-28212: nginx:1.24 security update (IMPORTANT)
BDU:2026-07182
Уязвимость модуля ngx_http_rewrite_module веб-серверов NGINX Plus и NGINX Open Source, позволяющая нарушителю выполнить произвольный код или вызвать отказ в обслуживании
ROS-20260626-73-0020
Уязвимость angie
ROS-20260609-73-0007
Уязвимость nginx
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-h78r-86c6-jgp4 NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite directive uses a regex pattern with distinct, overlapping Perl-Compatible Regular Expression (PCRE) captures (for example, ^/((.*))$) and a replacement string that references multiple such captures (for example, $1$2) in a redirect or arguments context. An unauthenticated attacker along with conditions beyond their control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | CVSS3: 8.1 | 10% Низкий | 2 месяца назад | |
CVE-2026-9256 NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite directive uses a regex pattern with distinct, overlapping Perl-Compatible Regular Expression (PCRE) captures (for example, ^/((.*))$) and a replacement string that references multiple such captures (for example, $1$2) in a redirect or arguments context. An unauthenticated attacker along with conditions beyond their control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | CVSS3: 8.1 | 10% Низкий | 2 месяца назад | |
CVE-2026-9256 NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite directive uses a regex pattern with distinct, overlapping Perl-Compatible Regular Expression (PCRE) captures (for example, ^/((.*))$) and a replacement string that references multiple such captures (for example, $1$2) in a redirect or arguments context. An unauthenticated attacker along with conditions beyond their control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | CVSS3: 8.1 | 10% Низкий | 2 месяца назад | |
CVE-2026-9256 NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite directive uses a regex pattern with distinct, overlapping Perl-Compatible Regular Expression (PCRE) captures (for example, ^/((.*))$) and a replacement string that references multiple such captures (for example, $1$2) in a redirect or arguments context. An unauthenticated attacker along with conditions beyond their control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | CVSS3: 8.1 | 10% Низкий | 2 месяца назад | |
CVE-2026-9256 NGINX ngx_http_rewrite_module vulnerability | CVSS3: 8.1 | 10% Низкий | 2 месяца назад | |
CVE-2026-9256 NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ ... | CVSS3: 8.1 | 10% Низкий | 2 месяца назад | |
openSUSE-SU-2026:21107-1 Security update for nginx | 10% Низкий | около 1 месяца назад | ||
SUSE-SU-2026:2307-1 Security update for nginx | 10% Низкий | около 2 месяцев назад | ||
RLSA-2026:29874 Important: nginx security update | 10% Низкий | около 1 месяца назад | ||
RLSA-2026:29151 Important: nginx:1.26 security update | 10% Низкий | около 1 месяца назад | ||
RLSA-2026:28921 Important: nginx:1.24 security update | 10% Низкий | около 1 месяца назад | ||
RLSA-2026:28212 Important: nginx:1.24 security update | 10% Низкий | около 1 месяца назад | ||
ELSA-2026-29874 ELSA-2026-29874: nginx security update (IMPORTANT) | 9 дней назад | |||
ELSA-2026-29151 ELSA-2026-29151: nginx:1.26 security update (IMPORTANT) | около 1 месяца назад | |||
ELSA-2026-28973 ELSA-2026-28973: nginx security update (IMPORTANT) | около 1 месяца назад | |||
ELSA-2026-28921 ELSA-2026-28921: nginx:1.24 security update (IMPORTANT) | около 1 месяца назад | |||
ELSA-2026-28212 ELSA-2026-28212: nginx:1.24 security update (IMPORTANT) | около 1 месяца назад | |||
BDU:2026-07182 Уязвимость модуля ngx_http_rewrite_module веб-серверов NGINX Plus и NGINX Open Source, позволяющая нарушителю выполнить произвольный код или вызвать отказ в обслуживании | CVSS3: 8.1 | 10% Низкий | 2 месяца назад | |
ROS-20260626-73-0020 Уязвимость angie | CVSS3: 8.1 | 10% Низкий | около 1 месяца назад | |
ROS-20260609-73-0007 Уязвимость nginx | CVSS3: 8.1 | 10% Низкий | около 2 месяцев назад |
Уязвимостей на страницу