CVEs (16)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1F5 7Dos Nginx Gateway FabricNginx Ingress Controller+4 moreJun 22, 2026 Jun 17, 2026 6.3 MEDIUM· v4 4.8 MEDIUM· v3 N/A· v2 NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When content is served or proxied through a location block with both source_charset utf-8; and a charset directive (for example...Show more |
1F5 4Nginx Gateway Fabric Nginx Ingress ControllerNginx Instance Manager+1 moreJul 16, 2026 Jun 17, 2026 9.2 CRITICAL· v4 8.1 HIGH· v3 N/A· v2 NGINX Open Source has a vulnerability in the ngx_http_v3_module module. When NGINX Open Source is configured to use the HTTP/3 QUIC module, a remote unauthenticated attacker along with conditions beyond their control can...Show more |
1F5 9Dos Nginx App Protect DosNginx App Protect Waf+6 moreJul 15, 2026 Jun 17, 2026 9.2 CRITICAL· v4 8.1 HIGH· v3 N/A· v2 NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass directives are used to proxy...Show more |
1F5 9Dos Nginx App Protect DosNginx App Protect Waf+6 moreJun 18, 2026 May 13, 2026 8.3 HIGH· v4 7.4 HIGH· v3 N/A· v2 A vulnerability exists in the ngx_http_scgi_module and ngx_http_uwsgi_module modules that may result in excessive memory allocation or an over-read of data. When scgi_pass or uwsgi_pass is configured, an unauthenticated...Show more |
1F5 7Dos Nginx Gateway FabricNginx Ingress Controller+4 moreJul 15, 2026 May 13, 2026 9.2 CRITICAL· v4 8.1 HIGH· v3 N/A· v2 NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compati...Show more |
1F5 7Dos Nginx Gateway FabricNginx Ingress Controller+4 moreJun 18, 2026 May 13, 2026 6.3 MEDIUM· v4 4.8 MEDIUM· v3 N/A· v2 NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When charset, source_charset, and charset_map and proxy_pass with disabled buffering ("off") directives are configured, unauthe...Show more |
1F5 4Nginx Gateway Fabric Nginx Ingress ControllerNginx Instance Manager+1 moreJun 18, 2026 May 13, 2026 6.3 MEDIUM· v4 5.8 MEDIUM· v3 N/A· v2 When NGINX Open Source is configured to proxy HTTP/2 traffic by setting proxy_http_version to 2, and also uses proxy_set_body, an attacker may be able to inject frame headers and payload bytes to the upstream peer. Note...Show more |
1F5 7Dos Nginx Gateway FabricNginx Ingress Controller+4 moreJun 23, 2026 May 13, 2026 6.3 MEDIUM· v4 4.8 MEDIUM· v3 N/A· v2 NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssl_module module when the ssl_verify_client directive is set to "on" or "optional," and the ssl_ocsp directive is set to "on" or the leaf parameters...Show more |
1F5 7Dos Nginx Gateway FabricNginx Ingress Controller+4 moreJun 29, 2026 May 13, 2026 6.9 MEDIUM· v4 6.5 MEDIUM· v3 N/A· v2 When NGINX Plus or NGINX Open Source are configured to use the HTTP/3 QUIC module, an attacker may be able to spoof their source IP address allowing for bypass of authorization or bypass of rate limiting. Note: Software...Show more |
1F5 5Nginx Gateway Fabric Nginx Ingress ControllerNginx Instance Manager+2 moreJun 17, 2026 Feb 4, 2026 8.2 HIGH· v4 5.9 MEDIUM· v3 N/A· v2 A vulnerability exists in NGINX OSS and NGINX Plus when configured to proxy to upstream Transport Layer Security (TLS) servers. An attacker with a man-in-the-middle (MITM) position on the upstream server side—along with...Show more |
1F5 4Nginx Api Connectivity Manager Nginx Ingress ControllerNginx Instance Manager+1 moreJun 17, 2026 Nov 6, 2024 5.1 MEDIUM· v4 5.4 MEDIUM· v3 N/A· v2 A session fixation issue was discovered in the NGINX OpenID Connect reference implementation, where a nonce was not checked at login time. This flaw allows an attacker to fix a victim's session to an attacker-controlled...Show more |
1F5 2Nginx Agent Nginx Instance ManagerJun 17, 2026 Aug 22, 2024 6.9 MEDIUM· v4 4.9 MEDIUM· v3 N/A· v2 NGINX Agent's "config_dirs" restriction feature allows a highly privileged attacker to gain the ability to write/overwrite files outside of the designated secure directory. |
1F5 3Nginx Api Connectivity Manager Nginx Instance ManagerNginx Security MonitoringJun 17, 2026 May 3, 2023 N/A· v4 7.1 HIGH· v3 N/A· v2 NGINX Management Suite default file permissions are set such that an authenticated attacker may be able to modify sensitive files on NGINX Instance Manager and NGINX API Connectivity Manager. Note: Software versions w...Show more |
2F5 Netapp5Cloud Backup Nginx Api Connectivity ManagerNginx Instance Manager+2 moreJun 17, 2026 May 3, 2023 N/A· v4 8.1 HIGH· v3 N/A· v2 NGINX Management Suite may allow an authenticated attacker to gain access to configuration objects outside of their assigned environment. Note: Software versions which have reached End of Technical Support (EoTS) are...Show more |
1F5 2Nginx Agent Nginx Instance ManagerJun 17, 2026 Mar 29, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Insertion of Sensitive Information into log file vulnerability in NGINX Agent. NGINX Agent version 2.0 before 2.23.3 inserts sensitive information into a log file. An authenticated attacker with local access to read agen...Show more |
In versions 2.x before 2.3.1 and all versions of 1.x, when NGINX Instance Manager is in use, undisclosed requests can cause an increase in disk resource utilization. Note: Software versions which have reached End of Tech...Show more |