8.3
CVE-2026-56434
- EPSS 0.45%
- Veröffentlicht 15.07.2026 14:33:46
- Zuletzt bearbeitet 10.08.2026 15:27:56
- Erkennungen
NGINX ngx_http_ssi_module vulnerability
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssi_module module. This vulnerability may exist when the Server-Side Includes (SSI), proxy_pass, and proxy_buffering off directives are configured. With this configuration, an unauthenticated attacker with man-in-the-middle (MITM) ability to control responses from an upstream server may be able to cause a use-after-free in the NGINX worker process. This issue may lead to limited modification of memory or a restart of the NGINX worker process. Impact: This vulnerability may allow remote attackers to have limited control to modify memory contents or restart the NGINX worker process. There is no control plane exposure; this is a data plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
F5 ≫ Nginx Gateway Fabric Version >= 1.3.0 <= 1.6.2
F5 ≫ Nginx Gateway Fabric Version >= 2.0.0 < 2.6.7
F5 ≫ Nginx Ingress Controller SwEdition continuous_releases Version >= 3.5.0 <= 3.7.2
F5 ≫ Nginx Ingress Controller SwEdition continuous_releases Version >= 5.0.0 < 5.5.3
F5 ≫ Nginx Ingress Controller SwEdition long-term_support Version >= 2026-lts-r1 < 2026-lts-r4
F5 ≫ Nginx Ingress Controller Version 4.0.0 SwEdition continuous_releases
F5 ≫ Nginx Ingress Controller Version 4.0.1 SwEdition continuous_releases
F5 ≫ Nginx Plus Version >= 37.0.0.1 < 37.0.3.1
F5 ≫ Nginx Plus Version >= r33 < r36
F5 ≫ Nginx Plus Version r36 Update -
F5 ≫ Nginx Plus Version r36 Update p1
F5 ≫ Nginx Plus Version r36 Update p2
F5 ≫ Nginx Plus Version r36 Update p3
F5 ≫ Nginx Plus Version r36 Update p4
F5 ≫ Nginx Plus Version r36 Update p5
F5 ≫ Nginx Plus Version r36 Update p6
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.45% | 0.367 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| F5 | 8.3 | 0 | 0 |
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
| F5 | 6.5 | 2.2 | 4.2 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H
|
CWE-416 Use After Free
The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
https://my.f5.com/manage/s/article/K000162098