Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 12

Количество 12

fstec логотип

BDU:2026-06961

3 месяца назад

Уязвимость модуля ngx_http_ssl_module веб-серверов NGINX Plus и NGINX Open Source, позволяющая нарушителю оказать воздействие на конфиденциальность и доступность защищаемой информации

CVSS3: 4.8
EPSS: Низкий
redos логотип

ROS-20260626-73-0039

около 1 месяца назад

Уязвимость angie

CVSS3: 4.8
EPSS: Низкий
redos логотип

ROS-20260609-73-0009

около 2 месяцев назад

Уязвимость nginx

CVSS3: 4.8
EPSS: Низкий
ubuntu логотип

CVE-2026-40701

3 месяца назад

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssl_module module when the ssl_verify_client directive is set to "on" or "optional," and the ssl_ocsp directive is set to "on" or the leaf parameters are configured with a resolver. With this configuration, an unauthenticated attacker can send requests along with conditions beyond its control that may cause a heap-use-after-free error in the NGINX worker process. This vulnerability may result in limited modification of data or the NGINX worker process restarting. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 4.8
EPSS: Низкий
redhat логотип

CVE-2026-40701

3 месяца назад

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssl_module module when the ssl_verify_client directive is set to "on" or "optional," and the ssl_ocsp directive is set to "on" or the leaf parameters are configured with a resolver. With this configuration, an unauthenticated attacker can send requests along with conditions beyond its control that may cause a heap-use-after-free error in the NGINX worker process. This vulnerability may result in limited modification of data or the NGINX worker process restarting.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 4.8
EPSS: Низкий
nvd логотип

CVE-2026-40701

3 месяца назад

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssl_module module when the ssl_verify_client directive is set to "on" or "optional," and the ssl_ocsp directive is set to "on" or the leaf parameters are configured with a resolver. With this configuration, an unauthenticated attacker can send requests along with conditions beyond its control that may cause a heap-use-after-free error in the NGINX worker process. This vulnerability may result in limited modification of data or the NGINX worker process restarting.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 4.8
EPSS: Низкий
msrc логотип

CVE-2026-40701

3 месяца назад

NGINX ngx_http_ssl_module vulnerability

CVSS3: 4.8
EPSS: Низкий
debian логотип

CVE-2026-40701

3 месяца назад

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ ...

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-x88q-x2r7-vg3g

3 месяца назад

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssl_module module when the ssl_verify_client directive is set to "on" or "optional," and the ssl_ocsp directive is set to "on" or the leaf parameters are configured with a resolver. With this configuration, an unauthenticated attacker can send requests along with conditions beyond its control that may cause a heap-use-after-free error in the NGINX worker process. This vulnerability may result in limited modification of data or the NGINX worker process restarting.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 4.8
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20796-1

2 месяца назад

Security update for nginx

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2050-1

2 месяца назад

Security update for nginx

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2370-1

около 2 месяцев назад

Security update for nginx

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2026-06961

Уязвимость модуля ngx_http_ssl_module веб-серверов NGINX Plus и NGINX Open Source, позволяющая нарушителю оказать воздействие на конфиденциальность и доступность защищаемой информации

CVSS3: 4.8
1%
Низкий
3 месяца назад
redos логотип
ROS-20260626-73-0039

Уязвимость angie

CVSS3: 4.8
1%
Низкий
около 1 месяца назад
redos логотип
ROS-20260609-73-0009

Уязвимость nginx

CVSS3: 4.8
1%
Низкий
около 2 месяцев назад
ubuntu логотип
CVE-2026-40701

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssl_module module when the ssl_verify_client directive is set to "on" or "optional," and the ssl_ocsp directive is set to "on" or the leaf parameters are configured with a resolver. With this configuration, an unauthenticated attacker can send requests along with conditions beyond its control that may cause a heap-use-after-free error in the NGINX worker process. This vulnerability may result in limited modification of data or the NGINX worker process restarting. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 4.8
1%
Низкий
3 месяца назад
redhat логотип
CVE-2026-40701

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssl_module module when the ssl_verify_client directive is set to "on" or "optional," and the ssl_ocsp directive is set to "on" or the leaf parameters are configured with a resolver. With this configuration, an unauthenticated attacker can send requests along with conditions beyond its control that may cause a heap-use-after-free error in the NGINX worker process. This vulnerability may result in limited modification of data or the NGINX worker process restarting.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 4.8
1%
Низкий
3 месяца назад
nvd логотип
CVE-2026-40701

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssl_module module when the ssl_verify_client directive is set to "on" or "optional," and the ssl_ocsp directive is set to "on" or the leaf parameters are configured with a resolver. With this configuration, an unauthenticated attacker can send requests along with conditions beyond its control that may cause a heap-use-after-free error in the NGINX worker process. This vulnerability may result in limited modification of data or the NGINX worker process restarting.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 4.8
1%
Низкий
3 месяца назад
msrc логотип
CVE-2026-40701

NGINX ngx_http_ssl_module vulnerability

CVSS3: 4.8
1%
Низкий
3 месяца назад
debian логотип
CVE-2026-40701

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ ...

CVSS3: 4.8
1%
Низкий
3 месяца назад
github логотип
GHSA-x88q-x2r7-vg3g

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssl_module module when the ssl_verify_client directive is set to "on" or "optional," and the ssl_ocsp directive is set to "on" or the leaf parameters are configured with a resolver. With this configuration, an unauthenticated attacker can send requests along with conditions beyond its control that may cause a heap-use-after-free error in the NGINX worker process. This vulnerability may result in limited modification of data or the NGINX worker process restarting.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 4.8
1%
Низкий
3 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:20796-1

Security update for nginx

2 месяца назад
suse-cvrf логотип
SUSE-SU-2026:2050-1

Security update for nginx

2 месяца назад
suse-cvrf логотип
SUSE-SU-2026:2370-1

Security update for nginx

около 2 месяцев назад

Уязвимостей на страницу