CVE-2026-60005
- EPSS 0.71%
- Veröffentlicht 15.07.2026 15:04:21
- Zuletzt bearbeitet 11.08.2026 15:09:03
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module. When the slice directive and unnamed regex captures are configured or when a background cache update happens, unauthenticated attackers can send requests that ...
CVE-2026-56434
- EPSS 0.45%
- Veröffentlicht 15.07.2026 14:33:46
- Zuletzt bearbeitet 10.08.2026 15:27:56
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssi_module module. This vulnerability may exist when the Server-Side Includes (SSI), proxy_pass, and proxy_buffering off directives are configured. With this configuration, an unau...
CVE-2026-60065
- EPSS 0.27%
- Veröffentlicht 15.07.2026 14:33:46
- Zuletzt bearbeitet 10.08.2026 15:27:53
When NGINX Plus is configured to use the Message Queuing Telemetry Transport (MQTT) filter module (ngx_stream_mqtt_filter_module), unauthenticated attackers can send requests with conditions beyond the attacker's control to cause a heap buffer over-r...
CVE-2026-42533
- EPSS 3.51%
- Veröffentlicht 15.07.2026 14:33:45
- Zuletzt bearbeitet 10.08.2026 15:28:01
A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the map's regex capture variables before referencing the map output variable. Alternatively, the same result could ...
CVE-2026-42055
- EPSS 4.02%
- Veröffentlicht 17.06.2026 14:04:32
- Zuletzt bearbeitet 25.08.2026 13:19:00
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass directives are used to proxy HTTP/2 traffic, the ignore_in...
CVE-2026-48142
- EPSS 0.68%
- Veröffentlicht 17.06.2026 14:04:32
- Zuletzt bearbeitet 11.08.2026 15:03:44
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When content is served or proxied through a location block with both source_charset utf-8; and a charset directive (for example, charset koi8-r;) configured,...
CVE-2026-9256
- EPSS 9.96%
- Veröffentlicht 22.05.2026 14:11:41
- Zuletzt bearbeitet 25.08.2026 13:19:33
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite directive uses a regex pattern with distinct, overlapping Perl-Compatible Regular Expression (PCRE) captures (for ex...
CVE-2026-40460
- EPSS 0.37%
- Veröffentlicht 13.05.2026 14:12:45
- Zuletzt bearbeitet 29.06.2026 14:17:01
When NGINX Plus or NGINX Open Source are configured to use the HTTP/3 QUIC module, an attacker may be able to spoof their source IP address allowing for bypass of authorization or bypass of rate limiting. Note: Software versions which have reached E...
CVE-2026-42946
- EPSS 0.93%
- Veröffentlicht 13.05.2026 14:12:44
- Zuletzt bearbeitet 16.06.2026 19:58:09
A vulnerability exists in the ngx_http_scgi_module and ngx_http_uwsgi_module modules that may result in excessive memory allocation or an over-read of data. When scgi_pass or uwsgi_pass is configured, an unauthenticated attacker with man-in-the-middl...
CVE-2026-40701
- EPSS 0.69%
- Veröffentlicht 13.05.2026 14:12:43
- Zuletzt bearbeitet 23.06.2026 13:57:51
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssl_module module when the ssl_verify_client directive is set to "on" or "optional," and the ssl_ocsp directive is set to "on" or the leaf parameters are configured with a resolver...