CVE-2026-42926
- EPSS 0.02%
- Veröffentlicht 13.05.2026 14:12:45
- Zuletzt bearbeitet 13.05.2026 16:27:11
When NGINX Open Source is configured to proxy HTTP/2 traffic by setting proxy_http_version to 2, and also uses proxy_set_body, an attacker may be able to inject frame headers and payload bytes to the upstream peer. Note: Software versions which have...
CVE-2026-40460
- EPSS 0.02%
- Veröffentlicht 13.05.2026 14:12:45
- Zuletzt bearbeitet 13.05.2026 16:27:11
When NGINX Plus or NGINX Open Source are configured to use the HTTP/3 QUIC module, an attacker may be able to spoof their source IP address allowing for bypass of authorization or bypass of rate limiting. Note: Software versions which have reached E...
CVE-2026-28755
- EPSS 0.01%
- Veröffentlicht 24.03.2026 14:13:26
- Zuletzt bearbeitet 26.03.2026 14:09:37
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_stream_ssl_module module due to the improper handling of revoked certificates when configured with the ssl_verify_client on and ssl_ocsp on directives, allowing the TLS handshake to suc...
CVE-2026-32647
- EPSS 0.01%
- Veröffentlicht 24.03.2026 14:13:25
- Zuletzt bearbeitet 26.03.2026 21:11:50
NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module module, which might allow an attacker to trigger a buffer over-read or over-write to the NGINX worker memory resulting in its termination or possibly code execution, usi...
CVE-2026-27784
- EPSS 0.01%
- Veröffentlicht 24.03.2026 14:13:25
- Zuletzt bearbeitet 30.03.2026 13:59:42
The 32-bit implementation of NGINX Open Source has a vulnerability in the ngx_http_mp4_module module, which might allow an attacker to over-read or over-write NGINX worker memory resulting in its termination, using a specially crafted MP4 file. The i...
CVE-2025-53859
- EPSS 0.03%
- Veröffentlicht 13.08.2025 14:46:55
- Zuletzt bearbeitet 04.11.2025 22:16:27
NGINX Open Source and NGINX Plus have a vulnerability in the ngx_mail_smtp_module that might allow an unauthenticated attacker to over-read NGINX SMTP authentication process memory; as a result, the server side may leak arbitrary bytes sent in a requ...
CVE-2025-23419
- EPSS 2.86%
- Veröffentlicht 05.02.2025 18:15:33
- Zuletzt bearbeitet 27.01.2026 13:30:41
When multiple server blocks are configured to share the same IP address and port, an attacker can use session resumption to bypass client certificate authentication requirements on these servers. This vulnerability arises when TLS Session Tickets ht...
CVE-2023-44487
- EPSS 94.4%
- Veröffentlicht 10.10.2023 14:15:10
- Zuletzt bearbeitet 12.05.2026 15:10:32
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
CVE-2022-41742
- EPSS 0.1%
- Veröffentlicht 19.10.2022 22:15:12
- Zuletzt bearbeitet 21.11.2024 07:23:46
NGINX Open Source before versions 1.23.2 and 1.22.1, NGINX Open Source Subscription before versions R2 P1 and R1 P1, and NGINX Plus before versions R27 P1 and R26 P1 have a vulnerability in the module ngx_http_mp4_module that might allow a local atta...
CVE-2022-41741
- EPSS 0.83%
- Veröffentlicht 19.10.2022 22:15:12
- Zuletzt bearbeitet 21.11.2024 07:23:46
NGINX Open Source before versions 1.23.2 and 1.22.1, NGINX Open Source Subscription before versions R2 P1 and R1 P1, and NGINX Plus before versions R27 P1 and R26 P1 have a vulnerability in the module ngx_http_mp4_module that might allow a local atta...