Skip to main content

Vendor/product archive

f5 / nginx_open_source CVEs

Beta · best-effort

25 CVEs tagged to f5 / nginx_open_source4 Critical, 8 High, 13 Medium, 0 Low, 0 Unrated.

CVE-2026-42055

Published Jun 17, 2026

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2…

CVSS 9.2 · Critical
evidence mentions
15
Buzz score
47.7

CVE-2026-9256

Published May 22, 2026

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite directive uses a regex pattern with distinct,…

CVSS 9.2 · Critical
evidence mentions
16
Buzz score
48.3
Vendor/product tagsBeta · best-effort

CVE-2026-32647

Published Mar 24, 2026

NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module module, which might allow an attacker to trigger a buffer over-read or over-write to the NGINX wor…

CVSS 8.5 · High
evidence mentions
19
Buzz score
43.0
Vendor/product tagsBeta · best-effort

CVE-2026-28755

Published Mar 24, 2026

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_stream_ssl_module module due to the improper handling of revoked certificates when configured with the ssl_verify_…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-28753

Published Mar 24, 2026

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_mail_smtp_module module due to the improper handling of CRLF sequences in DNS responses. This allows an attacker-c…

CVSS 6.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-27784

Published Mar 24, 2026

The 32-bit implementation of NGINX Open Source has a vulnerability in the ngx_http_mp4_module module, which might allow an attacker to over-read or over-write NGINX worker memory…

CVSS 8.5 · High
evidence mentions
19
Buzz score
43.0
Vendor/product tagsBeta · best-effort

CVE-2026-27654

Published Mar 24, 2026

NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_dav_module module that might allow an attacker to trigger a buffer overflow to the NGINX worker process; this…

CVSS 8.8 · High
evidence mentions
19
Buzz score
48.5
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-27651

Published Mar 24, 2026

When the ngx_mail_auth_http_module module is enabled on NGINX Plus or NGINX Open Source, undisclosed requests can cause worker processes to terminate. This issue may occur when (1…

CVSS 8.7 · High
evidence mentions
19
Buzz score
43.0
Vendor/product tagsBeta · best-effort

CVE-2025-53859

Published Aug 13, 2025

NGINX Open Source and NGINX Plus have a vulnerability in the ngx_mail_smtp_module that might allow an unauthenticated attacker to over-read NGINX SMTP authentication process memor…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-7347

Published Aug 14, 2024

NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module, which might allow an attacker to over-read NGINX worker memory resulting in its termination, usin…

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-24990

Published Feb 14, 2024

When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed requests can cause NGINX worker processes to terminate. Note: The HTTP/3 QUIC module is not…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-24989

Published Feb 14, 2024

When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed requests can cause NGINX worker processes to terminate. Note: The HTTP/3 QUIC module is not…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 25 CVEsPage 1 of 1