CVEs (42)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Apache DebianF53Debian Linux Http ServerNginxJul 23, 2026 Jun 8, 2026 N/A· v4 7.5 HIGH· v3 N/A· v2 Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via malicious HTTP requests.
This issue affects Apache HTTP Server: from 2.4.17 through 2.4.67. |
2Debian F53Debian Linux NginxNginx PlusJun 17, 2026 Feb 5, 2025 5.3 MEDIUM· v4 4.3 MEDIUM· v3 N/A· v2 When multiple server blocks are configured to share the same IP address and port, an attacker can use session resumption to bypass client certificate authentication requirements on these servers. This vulnerability arise...Show more |
33Akka AmazonApache+30 more165.net 3scale Api Management PlatformAdvanced Cluster Management For Kubernetes+162 moreJun 17, 2026 Oct 10, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. |
3Debian F5Fedoraproject4Debian Linux FedoraNginx+1 moreJun 17, 2026 Oct 19, 2022 N/A· v4 7.1 HIGH· v3 N/A· v2 NGINX Open Source before versions 1.23.2 and 1.22.1, NGINX Open Source Subscription before versions R2 P1 and R1 P1, and NGINX Plus before versions R27 P1 and R26 P1 have a vulnerability in the module ngx_http_mp4_module...Show more |
3Debian F5Fedoraproject4Debian Linux FedoraNginx+1 moreJun 17, 2026 Oct 19, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 NGINX Open Source before versions 1.23.2 and 1.22.1, NGINX Open Source Subscription before versions R2 P1 and R1 P1, and NGINX Plus before versions R27 P1 and R26 P1 have a vulnerability in the module ngx_http_mp4_module...Show more |
5Debian F5Fedoraproject+2 more5Debian Linux FedoraNginx+2 moreJun 17, 2026 Mar 23, 2022 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 ALPACA is an application layer protocol content confusion attack, exploiting TLS servers implementing different protocols but using compatible certificates, such as multi-domain or wildcard certificates. A MiTM attacker...Show more |
NGINX before 1.13.6 has a buffer overflow for years that exceed four digits, as demonstrated by a file with a modification date in 1969 that causes an integer overflow (or a false modification date far in the future), wh...Show more |
5F5 FedoraprojectNetapp+2 more13Blockchain Platform Communications Control Plane MonitorCommunications Fraud Monitor+10 moreJun 17, 2026 Jun 1, 2021 N/A· v4 7.7 HIGH· v3 6.8 MEDIUM· v2 A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cause 1-byte memory overwrite, resulting in worker process crash or potential other...Show more |
5Apple CanonicalF5+2 more5Cloud Backup LeapNginx+2 moreJun 17, 2026 Jan 9, 2020 N/A· v4 5.3 MEDIUM· v3 4.3 MEDIUM· v2 NGINX before 1.17.7, with certain error_page configurations, allows HTTP request smuggling, as demonstrated by the ability of an attacker to read unauthorized web pages in environments where NGINX is being fronted by a l...Show more |
nginx http proxy module does not verify peer identity of https origin server which could facilitate man-in-the-middle attack (MITM) |
12Apache AppleCanonical+9 more19Debian Linux Diskstation ManagerEnterprise Linux+16 moreJun 17, 2026 Aug 13, 2019 N/A· v4 6.5 MEDIUM· v3 6.8 MEDIUM· v2 Some HTTP/2 implementations are vulnerable to a header leak, potentially leading to a denial of service. The attacker sends a stream of headers with a 0-length header name and 0-length header value, optionally Huffman en...Show more |
12Apache AppleCanonical+9 more20Debian Linux Diskstation ManagerEnterprise Communications Broker+17 moreJun 17, 2026 Aug 13, 2019 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 Some HTTP/2 implementations are vulnerable to resource loops, potentially leading to a denial of service. The attacker creates multiple request streams and continually shuffles the priority of the streams in a way that c...Show more |
12Apache AppleCanonical+9 more20Debian Linux Diskstation ManagerEnterprise Communications Broker+17 moreJun 17, 2026 Aug 13, 2019 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of service. The attacker requests a large amount of data from a specified res...Show more |
5Apple CanonicalDebian+2 more5Debian Linux LeapNginx+2 moreNov 21, 2024 Nov 7, 2018 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 nginx before versions 1.15.6, 1.14.1 has a vulnerability in the ngx_http_mp4_module, which might allow an attacker to cause infinite loop in a worker process, cause a worker process crash, or might result in worker proce...Show more |
4Apple CanonicalDebian+1 more4Debian Linux NginxUbuntu Linux+1 moreNov 21, 2024 Nov 7, 2018 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive CPU usage. This issue affects nginx compiled with the ngx_http_v2_module (not compiled by default)...Show more |
5Apple CanonicalDebian+2 more5Debian Linux LeapNginx+2 moreNov 21, 2024 Nov 7, 2018 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive memory consumption. This issue affects nginx compiled with the ngx_http_v2_module (not compiled by...Show more |
3Apple F5Puppet3Nginx Puppet EnterpriseXcodeMay 13, 2026 Jul 13, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable to integer overflow vulnerability in nginx range filter module resulting into leak of potentially sensitive information triggered by specially crafted...Show more |
The nginx package before 1.6.2-5+deb8u3 on Debian jessie, the nginx packages before 1.4.6-1ubuntu3.6 on Ubuntu 14.04 LTS, before 1.10.0-0ubuntu0.16.04.3 on Ubuntu 16.04 LTS, and before 1.10.1-0ubuntu1.1 on Ubuntu 16.10,...Show more |
3Canonical DebianF53Debian Linux NginxUbuntu LinuxMay 6, 2026 Jun 7, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 os/unix/ngx_files.c in nginx before 1.10.1 and 1.11.x before 1.11.1 allows remote attackers to cause a denial of service (NULL pointer dereference and worker process crash) via a crafted request, involving writing a clie...Show more |
5Apple CanonicalDebian+2 more5Debian Linux LeapNginx+2 moreMay 6, 2026 Feb 15, 2016 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 does not properly limit CNAME resolution, which allows remote attackers to cause a denial of service (worker process resource consumption) via vectors related to...Show more |