← Back

Nginx

nginx

Vendor: F5 • 42 CVEs

CVEs (42)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
5Apple
CanonicalDebian+2 more
5Debian Linux
LeapNginx+2 more
May 6, 2026
Feb 15, 2016
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Use-after-free vulnerability in the resolver in nginx 0.6.18 through 1.8.0 and 1.9.x before 1.9.10 allows remote attackers to cause a denial of service (worker process crash) or possibly have unspecified other impact via...Show more
Use-after-free vulnerability in the resolver in nginx 0.6.18 through 1.8.0 and 1.9.x before 1.9.10 allows remote attackers to cause a denial of service (worker process crash) or possibly have unspecified other impact via a crafted DNS response related to CNAME response processing.Show less
6Apple
CanonicalDebian+3 more
6Debian Linux
LeapNginx+3 more
May 6, 2026
Feb 15, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 allows remote attackers to cause a denial of service (invalid pointer dereference and worker process crash) via a crafted UDP DNS response.
1F5
1Nginx
May 6, 2026
Dec 29, 2014
N/A· v4
N/A· v3
6.8 MEDIUM· v2
The STARTTLS implementation in mail/ngx_mail_smtp_handler.c in the SMTP proxy in nginx 1.5.x and 1.6.x before 1.6.1 and 1.7.x before 1.7.4 does not properly restrict I/O buffering, which allows man-in-the-middle attacker...Show more
The STARTTLS implementation in mail/ngx_mail_smtp_handler.c in the SMTP proxy in nginx 1.5.x and 1.6.x before 1.6.1 and 1.7.x before 1.7.4 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted SMTP sessions by sending a cleartext command that is processed after TLS is in place, related to a "plaintext command injection" attack, a similar issue to CVE-2011-0411.Show less
2Debian
F5
2Debian Linux
Nginx
May 6, 2026
Dec 8, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
nginx 0.5.6 through 1.7.4, when using the same shared ssl_session_cache or ssl_session_ticket_key for multiple servers, can reuse a cached SSL session for an unrelated context, which allows remote attackers with certain...Show more
nginx 0.5.6 through 1.7.4, when using the same shared ssl_session_cache or ssl_session_ticket_key for multiple servers, can reuse a cached SSL session for an unrelated context, which allows remote attackers with certain privileges to conduct "virtual host confusion" attacks.Show less
1F5
1Nginx
May 6, 2026
Apr 29, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
The SPDY implementation in the ngx_http_spdy_module module in nginx 1.5.10 before 1.5.11, when running on a 32-bit platform, allows remote attackers to execute arbitrary code via a crafted request.
2F5
Opensuse
2Nginx
Opensuse
May 6, 2026
Mar 28, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
Heap-based buffer overflow in the SPDY implementation in nginx 1.3.15 before 1.4.7 and 1.5.x before 1.5.12 allows remote attackers to execute arbitrary code via a crafted request.
3F5
OpensuseSuse
5Lifecycle Management Server
NginxOpensuse+2 more
Apr 29, 2026
Nov 23, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
nginx 0.8.41 through 1.4.3 and 1.5.x before 1.5.7 allows remote attackers to bypass intended restrictions via an unescaped space character in a URI.
1F5
1Nginx
Apr 29, 2026
Oct 27, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
The default configuration of nginx, possibly 1.3.13 and earlier, uses world-readable permissions for the (1) access.log and (2) error.log files, which allows local users to obtain sensitive information by reading the fil...Show more
The default configuration of nginx, possibly 1.3.13 and earlier, uses world-readable permissions for the (1) access.log and (2) error.log files, which allows local users to obtain sensitive information by reading the files.Show less
2Debian
F5
2Debian Linux
Nginx
Apr 29, 2026
Jul 20, 2013
N/A· v4
N/A· v3
5.8 MEDIUM· v2
http/modules/ngx_http_proxy_module.c in nginx 1.1.4 through 1.2.8 and 1.3.0 through 1.4.0, when proxy_pass is used with untrusted HTTP servers, allows remote attackers to cause a denial of service (crash) and obtain sens...Show more
http/modules/ngx_http_proxy_module.c in nginx 1.1.4 through 1.2.8 and 1.3.0 through 1.4.0, when proxy_pass is used with untrusted HTTP servers, allows remote attackers to cause a denial of service (crash) and obtain sensitive information from worker process memory via a crafted proxy response, a similar vulnerability to CVE-2013-2028.Show less
2F5
Fedoraproject
2Fedora
Nginx
Apr 29, 2026
Jul 20, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
The ngx_http_parse_chunked function in http/ngx_http_parse.c in nginx 1.3.9 through 1.4.0 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a chunked Transfer-Encoding request wi...Show more
The ngx_http_parse_chunked function in http/ngx_http_parse.c in nginx 1.3.9 through 1.4.0 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a chunked Transfer-Encoding request with a large chunk size, which triggers an integer signedness error and a stack-based buffer overflow.Show less
1F5
1Nginx
Apr 29, 2026
Jul 26, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
nginx/Windows 1.3.x before 1.3.1 and 1.2.x before 1.2.1 allows remote attackers to bypass intended access restrictions and access restricted files via (1) a trailing . (dot) or (2) certain "$index_allocation" sequences i...Show more
nginx/Windows 1.3.x before 1.3.1 and 1.2.x before 1.2.1 allows remote attackers to bypass intended access restrictions and access restricted files via (1) a trailing . (dot) or (2) certain "$index_allocation" sequences in a request.Show less
2F5
Fedoraproject
2Fedora
Nginx
Apr 29, 2026
Apr 17, 2012
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Buffer overflow in ngx_http_mp4_module.c in the ngx_http_mp4_module module in nginx 1.0.7 through 1.0.14 and 1.1.3 through 1.1.18, when the mp4 directive is used, allows remote attackers to cause a denial of service (mem...Show more
Buffer overflow in ngx_http_mp4_module.c in the ngx_http_mp4_module module in nginx 1.0.7 through 1.0.14 and 1.1.3 through 1.1.18, when the mp4 directive is used, allows remote attackers to cause a denial of service (memory overwrite) or possibly execute arbitrary code via a crafted MP4 file.Show less
3Debian
F5Fedoraproject
3Debian Linux
FedoraNginx
Apr 29, 2026
Apr 17, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Use-after-free vulnerability in nginx before 1.0.14 and 1.1.x before 1.1.17 allows remote HTTP servers to obtain sensitive information from process memory via a crafted backend response, in conjunction with a client requ...Show more
Use-after-free vulnerability in nginx before 1.0.14 and 1.1.x before 1.1.17 allows remote HTTP servers to obtain sensitive information from process memory via a crafted backend response, in conjunction with a client request.Show less
3F5
FedoraprojectSuse
5Fedora
NginxStudio+2 more
Apr 29, 2026
Dec 8, 2011
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Heap-based buffer overflow in compression-pointer processing in core/ngx_resolver.c in nginx before 1.0.10 allows remote resolvers to cause a denial of service (daemon crash) or possibly have unspecified other impact via...Show more
Heap-based buffer overflow in compression-pointer processing in core/ngx_resolver.c in nginx before 1.0.10 allows remote resolvers to cause a denial of service (daemon crash) or possibly have unspecified other impact via a long response.Show less
7Canonical
DebianF5+4 more
9Debian Linux
FedoraLinux Enterprise+6 more
Apr 29, 2026
Dec 6, 2010
N/A· v4
N/A· v3
4.3 MEDIUM· v2
OpenSSL before 0.9.8q, and 1.0.x before 1.0.0c, when SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG is enabled, does not properly prevent modification of the ciphersuite in the session cache, which allows remote attackers to fo...Show more
OpenSSL before 0.9.8q, and 1.0.x before 1.0.0c, when SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG is enabled, does not properly prevent modification of the ciphersuite in the session cache, which allows remote attackers to force the downgrade to an unintended cipher via vectors involving sniffing network traffic to discover a session identifier.Show less
1F5
1Nginx
Apr 29, 2026
Jun 15, 2010
N/A· v4
N/A· v3
5.0 MEDIUM· v2
nginx 0.8.36 allows remote attackers to cause a denial of service (crash) via certain encoded directory traversal sequences that trigger memory corruption, as demonstrated using the "%c0.%c0." sequence.
1F5
1Nginx
Apr 29, 2026
Jun 15, 2010
N/A· v4
N/A· v3
5.0 MEDIUM· v2
nginx 0.8 before 0.8.40 and 0.7 before 0.7.66, when running on Windows, allows remote attackers to obtain source code or unparsed content of arbitrary files under the web document root by appending ::$DATA to the URI.
1F5
1Nginx
Apr 23, 2026
Jan 13, 2010
N/A· v4
N/A· v3
6.8 MEDIUM· v2
nginx 0.7.64 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP re...Show more
nginx 0.7.64 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape sequence for a terminal emulator.Show less
2F5
Nginx
2Nginx
Nginx
Apr 23, 2026
Nov 24, 2009
N/A· v4
N/A· v3
4.9 MEDIUM· v2
Directory traversal vulnerability in src/http/modules/ngx_http_dav_module.c in nginx (aka Engine X) before 0.7.63, and 0.8.x before 0.8.17, allows remote authenticated users to create or overwrite arbitrary files via a ....Show more
Directory traversal vulnerability in src/http/modules/ngx_http_dav_module.c in nginx (aka Engine X) before 0.7.63, and 0.8.x before 0.8.17, allows remote authenticated users to create or overwrite arbitrary files via a .. (dot dot) in the Destination HTTP header for the WebDAV (1) COPY or (2) MOVE method.Show less
2F5
Nginx
2Nginx
Nginx
Apr 23, 2026
Nov 24, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
src/http/ngx_http_parse.c in nginx (aka Engine X) 0.1.0 through 0.4.14, 0.5.x before 0.5.38, 0.6.x before 0.6.39, 0.7.x before 0.7.62, and 0.8.x before 0.8.14 allows remote attackers to cause a denial of service (NULL po...Show more
src/http/ngx_http_parse.c in nginx (aka Engine X) 0.1.0 through 0.4.14, 0.5.x before 0.5.38, 0.6.x before 0.6.39, 0.7.x before 0.7.62, and 0.8.x before 0.8.14 allows remote attackers to cause a denial of service (NULL pointer dereference and worker process crash) via a long URI.Show less