F5

Nginx Open Source

30 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Medienbericht
  • EPSS 0.73%
  • Veröffentlicht 13.05.2026 14:12:44
  • Zuletzt bearbeitet 13.05.2026 16:27:11

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When charset, source_charset, and charset_map and proxy_pass with disabled buffering ("off") directives are configured, unauthenticated attackers can send re...

Medienbericht
  • EPSS 0.93%
  • Veröffentlicht 13.05.2026 14:12:44
  • Zuletzt bearbeitet 16.06.2026 19:58:09

A vulnerability exists in the ngx_http_scgi_module and ngx_http_uwsgi_module modules that may result in excessive memory allocation or an over-read of data. When scgi_pass or uwsgi_pass is configured, an unauthenticated attacker with man-in-the-middl...

Medienbericht Exploit
  • EPSS 66.04%
  • Veröffentlicht 13.05.2026 14:12:43
  • Zuletzt bearbeitet 25.08.2026 13:19:03

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) ...

Medienbericht
  • EPSS 0.69%
  • Veröffentlicht 13.05.2026 14:12:43
  • Zuletzt bearbeitet 23.06.2026 13:57:51

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssl_module module when the ssl_verify_client directive is set to "on" or "optional," and the ssl_ocsp directive is set to "on" or the leaf parameters are configured with a resolver...

  • EPSS 0.94%
  • Veröffentlicht 24.03.2026 14:13:27
  • Zuletzt bearbeitet 15.07.2026 02:19:09

When the ngx_mail_auth_http_module module is enabled on NGINX Plus or NGINX Open Source, undisclosed requests can cause worker processes to terminate. This issue may occur when (1) CRAM-MD5 or APOP authentication is enabled, and (2) the authenticatio...

Medienbericht
  • EPSS 21.01%
  • Veröffentlicht 24.03.2026 14:13:26
  • Zuletzt bearbeitet 15.07.2026 02:19:09

NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_dav_module module that might allow an attacker to trigger a buffer overflow to the NGINX worker process; this vulnerability may result in termination of the NGINX worker process or...

  • EPSS 0.26%
  • Veröffentlicht 24.03.2026 14:13:26
  • Zuletzt bearbeitet 26.03.2026 21:15:24

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_mail_smtp_module module due to the improper handling of CRLF sequences in DNS responses. This allows an attacker-controlled DNS server to inject arbitrary headers into SMTP upstream req...

  • EPSS 0.13%
  • Veröffentlicht 24.03.2026 14:13:26
  • Zuletzt bearbeitet 26.03.2026 14:09:37

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_stream_ssl_module module due to the improper handling of revoked certificates when configured with the ssl_verify_client on and ssl_ocsp on directives, allowing the TLS handshake to suc...

Medienbericht
  • EPSS 0.92%
  • Veröffentlicht 24.03.2026 14:13:25
  • Zuletzt bearbeitet 15.07.2026 02:20:00

NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module module, which might allow an attacker to trigger a buffer over-read or over-write to the NGINX worker memory resulting in its termination or possibly code execution, usi...

  • EPSS 1.03%
  • Veröffentlicht 24.03.2026 14:13:25
  • Zuletzt bearbeitet 15.07.2026 02:19:10

The 32-bit implementation of NGINX Open Source has a vulnerability in the ngx_http_mp4_module module, which might allow an attacker to over-read or over-write NGINX worker memory resulting in its termination, using a specially crafted MP4 file. The i...