Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 174

Количество 174

rocky логотип

RLSA-2026:19372

4 месяца назад

Critical: nginx:1.26 security update

EPSS: Средний
rocky логотип

RLSA-2026:19371

4 месяца назад

Critical: nginx:1.24 security update

EPSS: Средний
rocky логотип

RLSA-2026:19159

4 месяца назад

Critical: nginx security update

EPSS: Средний
rocky логотип

RLSA-2026:18063

4 месяца назад

Critical: nginx security update

EPSS: Средний
rocky логотип

RLSA-2026:18041

4 месяца назад

Critical: nginx:1.24 security update

EPSS: Средний
rocky логотип

RLSA-2026:18029

4 месяца назад

Critical: nginx security update

EPSS: Средний
github логотип

GHSA-x88q-x2r7-vg3g

4 месяца назад

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssl_module module when the ssl_verify_client directive is set to "on" or "optional," and the ssl_ocsp directive is set to "on" or the leaf parameters are configured with a resolver. With this configuration, an unauthenticated attacker can send requests along with conditions beyond its control that may cause a heap-use-after-free error in the NGINX worker process. This vulnerability may result in limited modification of data or the NGINX worker process restarting.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-h7rq-f9gq-mc8r

4 месяца назад

When NGINX Plus or NGINX Open Source are configured to use the HTTP/3 QUIC module, an attacker may be able to spoof their source IP address allowing for bypass of authorization or bypass of rate limiting.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-gcgv-v5gf-c543

4 месяца назад

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond its control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, for systems with Address Space Layout Randomization (ASLR ) disabled, code execution is possible.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 8.1
EPSS: Средний
github логотип

GHSA-fm65-xrrr-c358

4 месяца назад

A vulnerability exists in the ngx_http_scgi_module and ngx_http_uwsgi_module modules that may result in excessive memory allocation or an over-read of data. When scgi_pass or uwsgi_pass is configured, an unauthenticated attacker with man-in-the-middle (MITM) ability to control responses from an upstream server may be able to read the memory of the NGINX worker process or restart it.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-6vmc-2wh4-77qp

4 месяца назад

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When charset, source_charset, and charset_map and proxy_pass with disabled buffering ("off") directives are configured, unauthenticated attackers can send requests that with conditions beyond the attackers' control to cause a heap buffer over-read in the NGINX worker process, leading to limited disclosure of memory or a restart.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-2388-jp8v-fg9w

3 месяца назад

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When content is served or proxied through a location block with both source_charset utf-8; and a charset directive (for example, charset koi8-r;) configured, remote, unauthenticated attackers can send requests (in conjunction with conditions beyond their control) to cause a heap buffer over-read in the NGINX worker process, leading to limited disclosure of memory or a restart. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 4.8
EPSS: Низкий
oracle-oval логотип

ELSA-2026-19374

3 месяца назад

ELSA-2026-19374: nginx security update (CRITICAL)

EPSS: Средний
oracle-oval логотип

ELSA-2026-19372

3 месяца назад

ELSA-2026-19372: nginx:1.26 security update (CRITICAL)

EPSS: Средний
oracle-oval логотип

ELSA-2026-19371

3 месяца назад

ELSA-2026-19371: nginx:1.24 security update (CRITICAL)

EPSS: Средний
oracle-oval логотип

ELSA-2026-19159

около 2 месяцев назад

ELSA-2026-19159: nginx security update (CRITICAL)

EPSS: Средний
oracle-oval логотип

ELSA-2026-18063

4 месяца назад

ELSA-2026-18063: nginx security update (CRITICAL)

EPSS: Средний
oracle-oval логотип

ELSA-2026-18041

4 месяца назад

ELSA-2026-18041: nginx:1.24 security update (CRITICAL)

EPSS: Средний
oracle-oval логотип

ELSA-2026-18029

4 месяца назад

ELSA-2026-18029: nginx security update (CRITICAL)

EPSS: Средний
ubuntu логотип

CVE-2026-48142

3 месяца назад

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When content is served or proxied through a location block with both source_charset utf-8; and a charset directive (for example, charset koi8-r;) configured, remote, unauthenticated attackers can send requests (in conjunction with conditions beyond their control) to cause a heap buffer over-read in the NGINX worker process, leading to limited disclosure of memory or a restart. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 4.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
rocky логотип
RLSA-2026:19372

Critical: nginx:1.26 security update

68%
Средний
4 месяца назад
rocky логотип
RLSA-2026:19371

Critical: nginx:1.24 security update

68%
Средний
4 месяца назад
rocky логотип
RLSA-2026:19159

Critical: nginx security update

68%
Средний
4 месяца назад
rocky логотип
RLSA-2026:18063

Critical: nginx security update

68%
Средний
4 месяца назад
rocky логотип
RLSA-2026:18041

Critical: nginx:1.24 security update

68%
Средний
4 месяца назад
rocky логотип
RLSA-2026:18029

Critical: nginx security update

68%
Средний
4 месяца назад
github логотип
GHSA-x88q-x2r7-vg3g

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssl_module module when the ssl_verify_client directive is set to "on" or "optional," and the ssl_ocsp directive is set to "on" or the leaf parameters are configured with a resolver. With this configuration, an unauthenticated attacker can send requests along with conditions beyond its control that may cause a heap-use-after-free error in the NGINX worker process. This vulnerability may result in limited modification of data or the NGINX worker process restarting.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 4.8
1%
Низкий
4 месяца назад
github логотип
GHSA-h7rq-f9gq-mc8r

When NGINX Plus or NGINX Open Source are configured to use the HTTP/3 QUIC module, an attacker may be able to spoof their source IP address allowing for bypass of authorization or bypass of rate limiting.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 6.5
0%
Низкий
4 месяца назад
github логотип
GHSA-gcgv-v5gf-c543

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond its control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, for systems with Address Space Layout Randomization (ASLR ) disabled, code execution is possible.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 8.1
68%
Средний
4 месяца назад
github логотип
GHSA-fm65-xrrr-c358

A vulnerability exists in the ngx_http_scgi_module and ngx_http_uwsgi_module modules that may result in excessive memory allocation or an over-read of data. When scgi_pass or uwsgi_pass is configured, an unauthenticated attacker with man-in-the-middle (MITM) ability to control responses from an upstream server may be able to read the memory of the NGINX worker process or restart it.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 6.5
1%
Низкий
4 месяца назад
github логотип
GHSA-6vmc-2wh4-77qp

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When charset, source_charset, and charset_map and proxy_pass with disabled buffering ("off") directives are configured, unauthenticated attackers can send requests that with conditions beyond the attackers' control to cause a heap buffer over-read in the NGINX worker process, leading to limited disclosure of memory or a restart.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 4.8
1%
Низкий
4 месяца назад
github логотип
GHSA-2388-jp8v-fg9w

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When content is served or proxied through a location block with both source_charset utf-8; and a charset directive (for example, charset koi8-r;) configured, remote, unauthenticated attackers can send requests (in conjunction with conditions beyond their control) to cause a heap buffer over-read in the NGINX worker process, leading to limited disclosure of memory or a restart. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 4.8
1%
Низкий
3 месяца назад
oracle-oval логотип
ELSA-2026-19374

ELSA-2026-19374: nginx security update (CRITICAL)

68%
Средний
3 месяца назад
oracle-oval логотип
ELSA-2026-19372

ELSA-2026-19372: nginx:1.26 security update (CRITICAL)

68%
Средний
3 месяца назад
oracle-oval логотип
ELSA-2026-19371

ELSA-2026-19371: nginx:1.24 security update (CRITICAL)

68%
Средний
3 месяца назад
oracle-oval логотип
ELSA-2026-19159

ELSA-2026-19159: nginx security update (CRITICAL)

68%
Средний
около 2 месяцев назад
oracle-oval логотип
ELSA-2026-18063

ELSA-2026-18063: nginx security update (CRITICAL)

68%
Средний
4 месяца назад
oracle-oval логотип
ELSA-2026-18041

ELSA-2026-18041: nginx:1.24 security update (CRITICAL)

68%
Средний
4 месяца назад
oracle-oval логотип
ELSA-2026-18029

ELSA-2026-18029: nginx security update (CRITICAL)

68%
Средний
4 месяца назад
ubuntu логотип
CVE-2026-48142

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When content is served or proxied through a location block with both source_charset utf-8; and a charset directive (for example, charset koi8-r;) configured, remote, unauthenticated attackers can send requests (in conjunction with conditions beyond their control) to cause a heap buffer over-read in the NGINX worker process, leading to limited disclosure of memory or a restart. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 4.8
1%
Низкий
3 месяца назад

Уязвимостей на страницу