Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 28

Количество 28

github логотип

GHSA-vxcv-h5wj-jxr5

2 месяца назад

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module. When the slice directive and unnamed regex captures are configured or when a background cache update happens, unauthenticated attackers can send requests that may cause uninitialized memory access in the NGINX worker process, leading to limited disclosure of memory or a restart. Impact: This vulnerability may allow remote, unauthenticated attackers to have limited control to disclose memory contents or restart the NGINX worker process. There is no control plane exposure; this is a data plane issue only. Note: The ngx_http_slice_module module is not enabled by default; it's enabled with the --with-http_slice_module configuration parameter. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-m73p-xg7q-m8f2

2 месяца назад

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssi_module module. This vulnerability may exist when the Server-Side Includes (SSI), proxy_pass, and proxy_buffering off directives are configured. With this configuration, an unauthenticated attacker with man-in-the-middle (MITM) ability to control responses from an upstream server may be able to cause a heap buffer over-read in the NGINX worker process. This issue may lead to limited modification of memory or a restart of the NGINX worker process. Impact: This vulnerability may allow remote attackers to have limited control to modify memory contents or restart the NGINX worker process. There is no control plane exposure; this is a data plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 6.5
EPSS: Низкий
fstec логотип

BDU:2026-10487

2 месяца назад

Уязвимость модуля ngx_http_slice_module HTTP-сервера NGINX Plus и NGINX Open Source, позволяющая нарушителю раскрыть защищаемую информацию или вызвать отказ в обслуживании

CVSS3: 8.2
EPSS: Низкий
fstec логотип

BDU:2026-10486

2 месяца назад

Уязвимость модуля ngx_http_ssi_module HTTP-сервера NGINX Plus и NGINX Open Source, позволяющая нарушителю изменить содержимое памяти рабочего процесса или вызвать отказ в обслуживании

CVSS3: 6.5
EPSS: Низкий
redos логотип

ROS-20260803-80-0010

около 1 месяца назад

Уязвимость nginx

CVSS3: 6.5
EPSS: Низкий
redos логотип

ROS-20260803-80-0009

около 1 месяца назад

Уязвимость nginx

CVSS3: 8.2
EPSS: Низкий
redos логотип

ROS-20260803-73-0011

около 1 месяца назад

Уязвимость nginx

CVSS3: 6.5
EPSS: Низкий
redos логотип

ROS-20260803-73-0010

около 1 месяца назад

Уязвимость nginx

CVSS3: 8.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-vxcv-h5wj-jxr5

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module. When the slice directive and unnamed regex captures are configured or when a background cache update happens, unauthenticated attackers can send requests that may cause uninitialized memory access in the NGINX worker process, leading to limited disclosure of memory or a restart. Impact: This vulnerability may allow remote, unauthenticated attackers to have limited control to disclose memory contents or restart the NGINX worker process. There is no control plane exposure; this is a data plane issue only. Note: The ngx_http_slice_module module is not enabled by default; it's enabled with the --with-http_slice_module configuration parameter. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 8.2
1%
Низкий
2 месяца назад
github логотип
GHSA-m73p-xg7q-m8f2

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssi_module module. This vulnerability may exist when the Server-Side Includes (SSI), proxy_pass, and proxy_buffering off directives are configured. With this configuration, an unauthenticated attacker with man-in-the-middle (MITM) ability to control responses from an upstream server may be able to cause a heap buffer over-read in the NGINX worker process. This issue may lead to limited modification of memory or a restart of the NGINX worker process. Impact: This vulnerability may allow remote attackers to have limited control to modify memory contents or restart the NGINX worker process. There is no control plane exposure; this is a data plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 6.5
0%
Низкий
2 месяца назад
fstec логотип
BDU:2026-10487

Уязвимость модуля ngx_http_slice_module HTTP-сервера NGINX Plus и NGINX Open Source, позволяющая нарушителю раскрыть защищаемую информацию или вызвать отказ в обслуживании

CVSS3: 8.2
1%
Низкий
2 месяца назад
fstec логотип
BDU:2026-10486

Уязвимость модуля ngx_http_ssi_module HTTP-сервера NGINX Plus и NGINX Open Source, позволяющая нарушителю изменить содержимое памяти рабочего процесса или вызвать отказ в обслуживании

CVSS3: 6.5
0%
Низкий
2 месяца назад
redos логотип
ROS-20260803-80-0010

Уязвимость nginx

CVSS3: 6.5
0%
Низкий
около 1 месяца назад
redos логотип
ROS-20260803-80-0009

Уязвимость nginx

CVSS3: 8.2
1%
Низкий
около 1 месяца назад
redos логотип
ROS-20260803-73-0011

Уязвимость nginx

CVSS3: 6.5
0%
Низкий
около 1 месяца назад
redos логотип
ROS-20260803-73-0010

Уязвимость nginx

CVSS3: 8.2
1%
Низкий
около 1 месяца назад

Уязвимостей на страницу