F5

Nginx Ingress Controller

23 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Medienbericht
  • EPSS 0.37%
  • Veröffentlicht 13.05.2026 14:12:45
  • Zuletzt bearbeitet 29.06.2026 14:17:01

When NGINX Plus or NGINX Open Source are configured to use the HTTP/3 QUIC module, an attacker may be able to spoof their source IP address allowing for bypass of authorization or bypass of rate limiting.  Note: Software versions which have reached E...

Medienbericht
  • EPSS 0.93%
  • Veröffentlicht 13.05.2026 14:12:44
  • Zuletzt bearbeitet 16.06.2026 19:58:09

A vulnerability exists in the ngx_http_scgi_module and ngx_http_uwsgi_module modules that may result in excessive memory allocation or an over-read of data. When scgi_pass or uwsgi_pass is configured, an unauthenticated attacker with man-in-the-middl...

Medienbericht Exploit
  • EPSS 66.04%
  • Veröffentlicht 13.05.2026 14:12:43
  • Zuletzt bearbeitet 17.08.2026 12:18:36

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) ...

Medienbericht
  • EPSS 0.69%
  • Veröffentlicht 13.05.2026 14:12:43
  • Zuletzt bearbeitet 23.06.2026 13:57:51

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssl_module module when the ssl_verify_client directive is set to "on" or "optional," and the ssl_ocsp directive is set to "on" or the leaf parameters are configured with a resolver...

  • EPSS 0.34%
  • Veröffentlicht 04.02.2026 15:02:06
  • Zuletzt bearbeitet 13.02.2026 21:35:01

A vulnerability exists in NGINX OSS and NGINX Plus when configured to proxy to upstream Transport Layer Security (TLS) servers. An attacker with a man-in-the-middle (MITM) position on the upstream server side—along with conditions beyond the attacker...

  • EPSS 0.42%
  • Veröffentlicht 17.12.2025 15:48:22
  • Zuletzt bearbeitet 08.01.2026 18:24:50

A vulnerability exists in NGINX Ingress Controller's nginx.org/rewrite-target annotation validation. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

  • EPSS 0.35%
  • Veröffentlicht 06.11.2024 17:15:13
  • Zuletzt bearbeitet 08.11.2024 19:51:49

A session fixation issue was discovered in the NGINX OpenID Connect reference implementation, where a nonce was not checked at login time. This flaw allows an attacker to fix a victim's session to an attacker-controlled account. As a result, although...

Warnung Medienbericht Exploit
  • EPSS 100%
  • Veröffentlicht 10.10.2023 14:15:10
  • Zuletzt bearbeitet 11.08.2026 19:37:30

The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.

  • EPSS 0.22%
  • Veröffentlicht 19.10.2022 22:15:12
  • Zuletzt bearbeitet 21.11.2024 07:23:46

NGINX Plus before versions R27 P1 and R26 P1 have a vulnerability in the module ngx_http_hls_module that might allow a local attacker to corrupt NGINX worker memory, resulting in its crash or potential other impact using a specially crafted audio or ...

  • EPSS 1.12%
  • Veröffentlicht 19.10.2022 22:15:12
  • Zuletzt bearbeitet 21.11.2024 07:23:46

NGINX Open Source before versions 1.23.2 and 1.22.1, NGINX Open Source Subscription before versions R2 P1 and R1 P1, and NGINX Plus before versions R27 P1 and R26 P1 have a vulnerability in the module ngx_http_mp4_module that might allow a local atta...