Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 19

Количество 19

github логотип

GHSA-m73p-xg7q-m8f2

2 месяца назад

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssi_module module. This vulnerability may exist when the Server-Side Includes (SSI), proxy_pass, and proxy_buffering off directives are configured. With this configuration, an unauthenticated attacker with man-in-the-middle (MITM) ability to control responses from an upstream server may be able to cause a heap buffer over-read in the NGINX worker process. This issue may lead to limited modification of memory or a restart of the NGINX worker process. Impact: This vulnerability may allow remote attackers to have limited control to modify memory contents or restart the NGINX worker process. There is no control plane exposure; this is a data plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2026-56434

2 месяца назад

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssi_module module. This vulnerability may exist when the Server-Side Includes (SSI), proxy_pass, and proxy_buffering off directives are configured. With this configuration, an unauthenticated attacker with man-in-the-middle (MITM) ability to control responses from an upstream server may be able to cause a use-after-free in the NGINX worker process. This issue may lead to limited modification of memory or a restart of the NGINX worker process. Impact: This vulnerability may allow remote attackers to have limited control to modify memory contents or restart the NGINX worker process. There is no control plane exposure; this is a data plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2026-56434

2 месяца назад

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssi_module module. This vulnerability may exist when the Server-Side Includes (SSI), proxy_pass, and proxy_buffering off directives are configured. With this configuration, an unauthenticated attacker with man-in-the-middle (MITM) ability to control responses from an upstream server may be able to cause a use-after-free in the NGINX worker process. This issue may lead to limited modification of memory or a restart of the NGINX worker process. Impact: This vulnerability may allow remote attackers to have limited control to modify memory contents or restart the NGINX worker process. There is no control plane exposure; this is a data plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-56434

2 месяца назад

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssi_module module. This vulnerability may exist when the Server-Side Includes (SSI), proxy_pass, and proxy_buffering off directives are configured. With this configuration, an unauthenticated attacker with man-in-the-middle (MITM) ability to control responses from an upstream server may be able to cause a use-after-free in the NGINX worker process. This issue may lead to limited modification of memory or a restart of the NGINX worker process. Impact: This vulnerability may allow remote attackers to have limited control to modify memory contents or restart the NGINX worker process. There is no control plane exposure; this is a data plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 6.5
EPSS: Низкий
msrc логотип

CVE-2026-56434

около 2 месяцев назад

NGINX ngx_http_ssi_module vulnerability

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2026-56434

2 месяца назад

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ ...

CVSS3: 6.5
EPSS: Низкий
fstec логотип

BDU:2026-10486

2 месяца назад

Уязвимость модуля ngx_http_ssi_module HTTP-сервера NGINX Plus и NGINX Open Source, позволяющая нарушителю изменить содержимое памяти рабочего процесса или вызвать отказ в обслуживании

CVSS3: 6.5
EPSS: Низкий
redos логотип

ROS-20260803-80-0010

около 1 месяца назад

Уязвимость nginx

CVSS3: 6.5
EPSS: Низкий
redos логотип

ROS-20260803-73-0011

около 1 месяца назад

Уязвимость nginx

CVSS3: 6.5
EPSS: Низкий
rocky логотип

RLSA-2026:59496

19 дней назад

Important: nginx:1.26 security update

EPSS: Низкий
rocky логотип

RLSA-2026:59490

20 дней назад

Important: nginx:1.24 security update

EPSS: Низкий
rocky логотип

RLSA-2026:59362

19 дней назад

Important: nginx security update

EPSS: Низкий
rocky логотип

RLSA-2026:59220

20 дней назад

Important: nginx security update

EPSS: Низкий
rocky логотип

RLSA-2026:59216

20 дней назад

Important: nginx:1.24 security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-59496

20 дней назад

ELSA-2026-59496: nginx:1.26 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-59490

14 дней назад

ELSA-2026-59490: nginx:1.24 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-59362

18 дней назад

ELSA-2026-59362: nginx security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-59220

20 дней назад

ELSA-2026-59220: nginx security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-59216

20 дней назад

ELSA-2026-59216: nginx:1.24 security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-m73p-xg7q-m8f2

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssi_module module. This vulnerability may exist when the Server-Side Includes (SSI), proxy_pass, and proxy_buffering off directives are configured. With this configuration, an unauthenticated attacker with man-in-the-middle (MITM) ability to control responses from an upstream server may be able to cause a heap buffer over-read in the NGINX worker process. This issue may lead to limited modification of memory or a restart of the NGINX worker process. Impact: This vulnerability may allow remote attackers to have limited control to modify memory contents or restart the NGINX worker process. There is no control plane exposure; this is a data plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 6.5
0%
Низкий
2 месяца назад
ubuntu логотип
CVE-2026-56434

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssi_module module. This vulnerability may exist when the Server-Side Includes (SSI), proxy_pass, and proxy_buffering off directives are configured. With this configuration, an unauthenticated attacker with man-in-the-middle (MITM) ability to control responses from an upstream server may be able to cause a use-after-free in the NGINX worker process. This issue may lead to limited modification of memory or a restart of the NGINX worker process. Impact: This vulnerability may allow remote attackers to have limited control to modify memory contents or restart the NGINX worker process. There is no control plane exposure; this is a data plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 6.5
0%
Низкий
2 месяца назад
redhat логотип
CVE-2026-56434

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssi_module module. This vulnerability may exist when the Server-Side Includes (SSI), proxy_pass, and proxy_buffering off directives are configured. With this configuration, an unauthenticated attacker with man-in-the-middle (MITM) ability to control responses from an upstream server may be able to cause a use-after-free in the NGINX worker process. This issue may lead to limited modification of memory or a restart of the NGINX worker process. Impact: This vulnerability may allow remote attackers to have limited control to modify memory contents or restart the NGINX worker process. There is no control plane exposure; this is a data plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 6.5
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-56434

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssi_module module. This vulnerability may exist when the Server-Side Includes (SSI), proxy_pass, and proxy_buffering off directives are configured. With this configuration, an unauthenticated attacker with man-in-the-middle (MITM) ability to control responses from an upstream server may be able to cause a use-after-free in the NGINX worker process. This issue may lead to limited modification of memory or a restart of the NGINX worker process. Impact: This vulnerability may allow remote attackers to have limited control to modify memory contents or restart the NGINX worker process. There is no control plane exposure; this is a data plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 6.5
0%
Низкий
2 месяца назад
msrc логотип
CVE-2026-56434

NGINX ngx_http_ssi_module vulnerability

CVSS3: 6.5
0%
Низкий
около 2 месяцев назад
debian логотип
CVE-2026-56434

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ ...

CVSS3: 6.5
0%
Низкий
2 месяца назад
fstec логотип
BDU:2026-10486

Уязвимость модуля ngx_http_ssi_module HTTP-сервера NGINX Plus и NGINX Open Source, позволяющая нарушителю изменить содержимое памяти рабочего процесса или вызвать отказ в обслуживании

CVSS3: 6.5
0%
Низкий
2 месяца назад
redos логотип
ROS-20260803-80-0010

Уязвимость nginx

CVSS3: 6.5
0%
Низкий
около 1 месяца назад
redos логотип
ROS-20260803-73-0011

Уязвимость nginx

CVSS3: 6.5
0%
Низкий
около 1 месяца назад
rocky логотип
RLSA-2026:59496

Important: nginx:1.26 security update

19 дней назад
rocky логотип
RLSA-2026:59490

Important: nginx:1.24 security update

20 дней назад
rocky логотип
RLSA-2026:59362

Important: nginx security update

19 дней назад
rocky логотип
RLSA-2026:59220

Important: nginx security update

20 дней назад
rocky логотип
RLSA-2026:59216

Important: nginx:1.24 security update

20 дней назад
oracle-oval логотип
ELSA-2026-59496

ELSA-2026-59496: nginx:1.26 security update (IMPORTANT)

20 дней назад
oracle-oval логотип
ELSA-2026-59490

ELSA-2026-59490: nginx:1.24 security update (IMPORTANT)

14 дней назад
oracle-oval логотип
ELSA-2026-59362

ELSA-2026-59362: nginx security update (IMPORTANT)

18 дней назад
oracle-oval логотип
ELSA-2026-59220

ELSA-2026-59220: nginx security update (IMPORTANT)

20 дней назад
oracle-oval логотип
ELSA-2026-59216

ELSA-2026-59216: nginx:1.24 security update (IMPORTANT)

20 дней назад

Уязвимостей на страницу