CVE-2026-42926
- EPSS 0.02%
- Veröffentlicht 13.05.2026 14:12:45
- Zuletzt bearbeitet 13.05.2026 16:27:11
When NGINX Open Source is configured to proxy HTTP/2 traffic by setting proxy_http_version to 2, and also uses proxy_set_body, an attacker may be able to inject frame headers and payload bytes to the upstream peer. Note: Software versions which have...
CVE-2026-40460
- EPSS 0.02%
- Veröffentlicht 13.05.2026 14:12:45
- Zuletzt bearbeitet 13.05.2026 16:27:11
When NGINX Plus or NGINX Open Source are configured to use the HTTP/3 QUIC module, an attacker may be able to spoof their source IP address allowing for bypass of authorization or bypass of rate limiting. Note: Software versions which have reached E...
CVE-2026-42946
- EPSS 0.04%
- Veröffentlicht 13.05.2026 14:12:44
- Zuletzt bearbeitet 13.05.2026 16:27:11
A vulnerability exists in the ngx_http_scgi_module and ngx_http_uwsgi_module modules that may result in excessive memory allocation or an over-read of data. When scgi_pass or uwsgi_pass is configured, an unauthenticated attacker with man-in-the-middl...
CVE-2026-42934
- EPSS 0.03%
- Veröffentlicht 13.05.2026 14:12:44
- Zuletzt bearbeitet 13.05.2026 16:27:11
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When charset, source_charset, and charset_map and proxy_pass with disabled buffering ("off") directives are configured, unauthenticated attackers can send re...
- EPSS 0.17%
- Veröffentlicht 13.05.2026 14:12:43
- Zuletzt bearbeitet 14.05.2026 20:17:05
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) ...
CVE-2026-40701
- EPSS 0.03%
- Veröffentlicht 13.05.2026 14:12:43
- Zuletzt bearbeitet 13.05.2026 16:27:11
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssl_module module when the ssl_verify_client directive is set to "on" or "optional," and the ssl_ocsp directive is set to "on" or the leaf parameters are configured with a resolver...
CVE-2026-27651
- EPSS 0.05%
- Veröffentlicht 24.03.2026 14:13:27
- Zuletzt bearbeitet 30.03.2026 14:02:05
When the ngx_mail_auth_http_module module is enabled on NGINX Plus or NGINX Open Source, undisclosed requests can cause worker processes to terminate. This issue may occur when (1) CRAM-MD5 or APOP authentication is enabled, and (2) the authenticatio...
CVE-2026-27654
- EPSS 0.04%
- Veröffentlicht 24.03.2026 14:13:26
- Zuletzt bearbeitet 26.03.2026 21:16:16
NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_dav_module module that might allow an attacker to trigger a buffer overflow to the NGINX worker process; this vulnerability may result in termination of the NGINX worker process or...
CVE-2026-28755
- EPSS 0.01%
- Veröffentlicht 24.03.2026 14:13:26
- Zuletzt bearbeitet 26.03.2026 14:09:37
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_stream_ssl_module module due to the improper handling of revoked certificates when configured with the ssl_verify_client on and ssl_ocsp on directives, allowing the TLS handshake to suc...
CVE-2026-28753
- EPSS 0.03%
- Veröffentlicht 24.03.2026 14:13:26
- Zuletzt bearbeitet 26.03.2026 21:15:24
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_mail_smtp_module module due to the improper handling of CRLF sequences in DNS responses. This allows an attacker-controlled DNS server to inject arbitrary headers into SMTP upstream req...