Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 19

Количество 19

fstec логотип

BDU:2026-08881

около 1 месяца назад

Уязвимость модулей ngx_http_proxy_v2_module и ngx_http_grpc_module веб-серверов NGINX Plus и NGINX Open Source, позволяющая нарушитлю выполнить произвольный код или вызвать отказ в обслуживании

CVSS3: 8.1
EPSS: Низкий
redos логотип

ROS-20260714-73-0059

17 дней назад

Уязвимость angie

CVSS3: 8.1
EPSS: Низкий
ubuntu логотип

CVE-2026-42055

около 1 месяца назад

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass directives are used to proxy HTTP/2 traffic, the ignore_invalid_headers directive is set to off, and the large_client_header_buffers directive size is larger than 2 megabytes. A remote, unauthenticated attacker, along with conditions beyond their control, could send large headers while creating an upstream request. This may cause a heap-based buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 8.1
EPSS: Низкий
redhat логотип

CVE-2026-42055

около 1 месяца назад

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass directives are used to proxy HTTP/2 traffic, the ignore_invalid_headers directive is set to off, and the large_client_header_buffers directive size is larger than 2 megabytes. A remote, unauthenticated attacker, along with conditions beyond their control, could send large headers while creating an upstream request. This may cause a heap-based buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2026-42055

около 1 месяца назад

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass directives are used to proxy HTTP/2 traffic, the ignore_invalid_headers directive is set to off, and the large_client_header_buffers directive size is larger than 2 megabytes. A remote, unauthenticated attacker, along with conditions beyond their control, could send large headers while creating an upstream request. This may cause a heap-based buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 8.1
EPSS: Низкий
msrc логотип

CVE-2026-42055

30 дней назад

NGINX ngx_http_proxy_v2_module and ngx_http_grpc_module vulnerability

CVSS3: 8.1
EPSS: Низкий
debian логотип

CVE-2026-42055

около 1 месяца назад

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ ...

CVSS3: 8.1
EPSS: Низкий
rocky логотип

RLSA-2026:38847

18 дней назад

Important: nginx:1.24 security, bug fix, and enhancement update

EPSS: Низкий
rocky логотип

RLSA-2026:36639

22 дня назад

Important: nginx:1.26 security, bug fix, and enhancement update

EPSS: Низкий
rocky логотип

RLSA-2026:36618

23 дня назад

Important: nginx:1.24 security, bug fix, and enhancement update

EPSS: Низкий
rocky логотип

RLSA-2026:36364

23 дня назад

Important: nginx security, bug fix, and enhancement update

EPSS: Низкий
github логотип

GHSA-78jw-ww3g-9wp7

около 1 месяца назад

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass directives are used to proxy HTTP/2 traffic, the ignore_invalid_headers directive is set to off, and the large_client_header_buffers directive size is larger than 2 megabytes. A remote, unauthenticated attacker, along with conditions beyond their control, could send large headers while creating an upstream request. This may cause a heap-based buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 8.1
EPSS: Низкий
oracle-oval логотип

ELSA-2026-38847

17 дней назад

ELSA-2026-38847: nginx:1.24 security, bug fix, and enhancement update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-36639

22 дня назад

ELSA-2026-36639: nginx:1.26 security, bug fix, and enhancement update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-36618

22 дня назад

ELSA-2026-36618: nginx:1.24 security, bug fix, and enhancement update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-36364

15 дней назад

ELSA-2026-36364: nginx security, bug fix, and enhancement update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-36331

18 дней назад

ELSA-2026-36331: nginx security, bug fix, and enhancement update (IMPORTANT)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3329-1

3 дня назад

Security update for nginx

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21439-1

7 дней назад

Security update for nginx

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2026-08881

Уязвимость модулей ngx_http_proxy_v2_module и ngx_http_grpc_module веб-серверов NGINX Plus и NGINX Open Source, позволяющая нарушитлю выполнить произвольный код или вызвать отказ в обслуживании

CVSS3: 8.1
4%
Низкий
около 1 месяца назад
redos логотип
ROS-20260714-73-0059

Уязвимость angie

CVSS3: 8.1
4%
Низкий
17 дней назад
ubuntu логотип
CVE-2026-42055

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass directives are used to proxy HTTP/2 traffic, the ignore_invalid_headers directive is set to off, and the large_client_header_buffers directive size is larger than 2 megabytes. A remote, unauthenticated attacker, along with conditions beyond their control, could send large headers while creating an upstream request. This may cause a heap-based buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 8.1
4%
Низкий
около 1 месяца назад
redhat логотип
CVE-2026-42055

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass directives are used to proxy HTTP/2 traffic, the ignore_invalid_headers directive is set to off, and the large_client_header_buffers directive size is larger than 2 megabytes. A remote, unauthenticated attacker, along with conditions beyond their control, could send large headers while creating an upstream request. This may cause a heap-based buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 8.1
4%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-42055

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass directives are used to proxy HTTP/2 traffic, the ignore_invalid_headers directive is set to off, and the large_client_header_buffers directive size is larger than 2 megabytes. A remote, unauthenticated attacker, along with conditions beyond their control, could send large headers while creating an upstream request. This may cause a heap-based buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 8.1
4%
Низкий
около 1 месяца назад
msrc логотип
CVE-2026-42055

NGINX ngx_http_proxy_v2_module and ngx_http_grpc_module vulnerability

CVSS3: 8.1
4%
Низкий
30 дней назад
debian логотип
CVE-2026-42055

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ ...

CVSS3: 8.1
4%
Низкий
около 1 месяца назад
rocky логотип
RLSA-2026:38847

Important: nginx:1.24 security, bug fix, and enhancement update

4%
Низкий
18 дней назад
rocky логотип
RLSA-2026:36639

Important: nginx:1.26 security, bug fix, and enhancement update

4%
Низкий
22 дня назад
rocky логотип
RLSA-2026:36618

Important: nginx:1.24 security, bug fix, and enhancement update

4%
Низкий
23 дня назад
rocky логотип
RLSA-2026:36364

Important: nginx security, bug fix, and enhancement update

4%
Низкий
23 дня назад
github логотип
GHSA-78jw-ww3g-9wp7

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass directives are used to proxy HTTP/2 traffic, the ignore_invalid_headers directive is set to off, and the large_client_header_buffers directive size is larger than 2 megabytes. A remote, unauthenticated attacker, along with conditions beyond their control, could send large headers while creating an upstream request. This may cause a heap-based buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 8.1
4%
Низкий
около 1 месяца назад
oracle-oval логотип
ELSA-2026-38847

ELSA-2026-38847: nginx:1.24 security, bug fix, and enhancement update (IMPORTANT)

17 дней назад
oracle-oval логотип
ELSA-2026-36639

ELSA-2026-36639: nginx:1.26 security, bug fix, and enhancement update (IMPORTANT)

22 дня назад
oracle-oval логотип
ELSA-2026-36618

ELSA-2026-36618: nginx:1.24 security, bug fix, and enhancement update (IMPORTANT)

22 дня назад
oracle-oval логотип
ELSA-2026-36364

ELSA-2026-36364: nginx security, bug fix, and enhancement update (IMPORTANT)

15 дней назад
oracle-oval логотип
ELSA-2026-36331

ELSA-2026-36331: nginx security, bug fix, and enhancement update (IMPORTANT)

18 дней назад
suse-cvrf логотип
SUSE-SU-2026:3329-1

Security update for nginx

3 дня назад
suse-cvrf логотип
openSUSE-SU-2026:21439-1

Security update for nginx

7 дней назад

Уязвимостей на страницу