Skip to main content

Vendor/product archive

f5 / nginx_plus CVEs

Beta · best-effort

25 CVEs tagged to f5 / nginx_plus3 Critical, 9 High, 13 Medium, 0 Low, 0 Unrated.

CVE-2026-42055

Published Jun 17, 2026

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2…

CVSS 9.2 · Critical
evidence mentions
14
Buzz score
47.1

CVE-2026-9256

Published May 22, 2026

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite directive uses a regex pattern with distinct,…

CVSS 9.2 · Critical
evidence mentions
16
Buzz score
48.3
Vendor/product tagsBeta · best-effort

CVE-2026-32647

Published Mar 24, 2026

NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module module, which might allow an attacker to trigger a buffer over-read or over-write to the NGINX wor…

CVSS 8.5 · High
evidence mentions
19
Buzz score
43.0
Vendor/product tagsBeta · best-effort

CVE-2026-28755

Published Mar 24, 2026

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_stream_ssl_module module due to the improper handling of revoked certificates when configured with the ssl_verify_…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-28753

Published Mar 24, 2026

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_mail_smtp_module module due to the improper handling of CRLF sequences in DNS responses. This allows an attacker-c…

CVSS 6.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-27654

Published Mar 24, 2026

NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_dav_module module that might allow an attacker to trigger a buffer overflow to the NGINX worker process; this…

CVSS 8.8 · High
evidence mentions
19
Buzz score
48.5
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-27651

Published Mar 24, 2026

When the ngx_mail_auth_http_module module is enabled on NGINX Plus or NGINX Open Source, undisclosed requests can cause worker processes to terminate. This issue may occur when (1…

CVSS 8.7 · High
evidence mentions
19
Buzz score
43.0
Vendor/product tagsBeta · best-effort

CVE-2025-53859

Published Aug 13, 2025

NGINX Open Source and NGINX Plus have a vulnerability in the ngx_mail_smtp_module that might allow an unauthenticated attacker to over-read NGINX SMTP authentication process memor…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-23419

Published Feb 5, 2025

When multiple server blocks are configured to share the same IP address and port, an attacker can use session resumption to bypass client certificate authentication requirements o…

CVSS 5.3 · Medium
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2024-7347

Published Aug 14, 2024

NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module, which might allow an attacker to over-read NGINX worker memory resulting in its termination, usin…

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-39792

Published Aug 14, 2024

When the NGINX Plus is configured to use the MQTT pre-read module, undisclosed requests can cause an increase in memory resource utilization.  Note: Software versions which have r…

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-24990

Published Feb 14, 2024

When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed requests can cause NGINX worker processes to terminate. Note: The HTTP/3 QUIC module is not…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-24989

Published Feb 14, 2024

When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed requests can cause NGINX worker processes to terminate. Note: The HTTP/3 QUIC module is not…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 25 CVEsPage 1 of 1