CVE-2022-41742
published 2022-10-19CVE-2022-41742: NGINX Open Source before versions 1.23.2 and 1.22.1, NGINX Open Source Subscription before versions R2 P1 and R1 P1, and NGINX Plus before versions R27 P1 and…
PriorityP431high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
EPSS
1.07%
61.1th percentile
NGINX Open Source before versions 1.23.2 and 1.22.1, NGINX Open Source Subscription before versions R2 P1 and R1 P1, and NGINX Plus before versions R27 P1 and R26 P1 have a vulnerability in the module ngx_http_mp4_module that might allow a local attacker to cause a worker process crash, or might result in worker process memory disclosure by using a specially crafted audio or video file. The issue affects only NGINX products that are built with the module ngx_http_mp4_module, when the mp4 directive is used in the configuration file. Further, the attack is possible only if an attacker can trigger processing of a specially crafted audio or video file with the module ngx_http_mp4_module.
Affected
35 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | nginx | < nginx 1.22.1-1 (bookworm) | nginx 1.22.1-1 (bookworm) |
| f5 | nginx | — | — |
| f5 | nginx | — | — |
| f5 | nginx | — | — |
| f5 | nginx | — | — |
| f5 | nginx | — | — |
| f5 | nginx | >= 0 < 1.18.0-6.1+deb11u3 | 1.18.0-6.1+deb11u3 |
| f5 | nginx | >= 0 < 1.22.1-1 | 1.22.1-1 |
| f5 | nginx | >= 0 < 1.22.1-1 | 1.22.1-1 |
| f5 | nginx | >= 0 < 1.22.1-1 | 1.22.1-1 |
| f5 | nginx | >= 0 < 1.14.0-0ubuntu1.11 | 1.14.0-0ubuntu1.11 |
| f5 | nginx | >= 0 < 1.18.0-0ubuntu1.4 | 1.18.0-0ubuntu1.4 |
| f5 | nginx | >= 0 < 1.18.0-6ubuntu14.3 | 1.18.0-6ubuntu14.3 |
| f5 | nginx | >= 0 < 1.4.6-1ubuntu3.9+esm4 | 1.4.6-1ubuntu3.9+esm4 |
| f5 | nginx | >= 0 < 1.10.3-0ubuntu0.16.04.5+esm5 | 1.10.3-0ubuntu0.16.04.5+esm5 |
| f5 | nginx | 1.1.3 – 1.22.0 | — |
| f5 | nginx | >= Mainline < 1.23.2 | 1.23.2 |
| f5 | nginx | >= Stable < 1.22.1 | 1.22.1 |
| f5 | nginx | r22 – r27 | — |
| f5 | nginx_ingress_controller | — | — |
| f5 | nginx_ingress_controller | 1.9.0 – 1.12.4 | — |
| f5 | nginx_ingress_controller | 2.0.0 – 2.4.0 | — |
| f5 | nginx_open_source_subscription | >= R1 < R1 P1 | R1 P1 |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
osv7.8HIGH
vendor_debian7.1HIGH
vendor_msrc7.1HIGH
vendor_redhat7.1HIGH
vendor_ubuntu7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Palo Alto
PAN-SA-2025-0006 Informational Bulletin: Impact of OSS CVEs in PAN-OS
vendor_paloalto·2025-02-12·CVSS 7.1
CVE-2015-5312 [HIGH] PAN-SA-2025-0006 Informational Bulletin: Impact of OSS CVEs in PAN-OS
PAN-SA-2025-0006 Informational Bulletin: Impact of OSS CVEs in PAN-OS
T he Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS software. While PAN-OS software may include the
CVEs: CVE-2015-5312, CVE-2016-4607, CVE-2016-4608, CVE-2016-4609, CVE-2016-4738, CVE-2018-1111, CVE-2018-14634, CVE-2018-18653, CVE-2019-0145, CVE-2019-8331, CVE-2020-0599, CVE-2020-14343, CVE-2020-14779, CVE-2020-27844, CVE-2020-29569, CVE-2021-21315, CVE-2021-27853, CVE-2021-27854, CVE-2021-27861, CVE-2021-27862, CVE-2021-3618, CVE-2021-3711, CVE-2022-2097, CVE-2022-22816, CVE-2022-40303, CVE-2022-41723, CVE-2022-41741, CVE-2022-41742, CVE-2023-3247, CVE-2023-38408, CVE-2023-44466, CVE-2023-50781, CVE-2023-50782, CVE-2024-12084, CV
CISA ICS
Siemens SINEC Traffic Analyzer
cisa_ics·2024-06-13
Siemens SINEC Traffic Analyzer
ICS Advisory
##
Siemens SINEC Traffic Analyzer
Release DateJune 13, 2024
Alert CodeICSA-24-165-13
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 8.7
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SINEC Traffic Analyzer
- Vulnerabilities: Out-of-bounds Write, Insufficient Session Expiration, Cross-Site Request Forgery (CSRF),
Ubuntu
nginx vulnerabilities
vendor_ubuntu·2022-11-15·CVSS 7.0
CVE-2022-41741 [HIGH] nginx vulnerabilities
Title: nginx vulnerabilities
Summary: Several security issues were fixed in nginx.
It was discovered that nginx incorrectly handled certain memory operations in
the ngx_http_mp4_module module. A local attacker could possibly use this issue
with a specially crafted mp4 file to cause nginx to crash, stop responding, or
access arbitrary memory. (CVE-2022-41741, CVE-2022-41742)
Instructions: In general, a standard system update will make all the necessary changes.
F5
CVE-2022-41742: NGINX Open Source before versions 1
vendor_f5·2022-10-19·CVSS 7.1
CVE-2022-41742 [HIGH] CWE-787 CVE-2022-41742: NGINX Open Source before versions 1
CVE-2022-41742: NGINX Open Source before versions 1
NGINX Open Source before versions 1.23.2 and 1.22.1, NGINX Open Source Subscription before versions R2 P1 and R1 P1, and NGINX Plus before versions R27 P1 and R26 P1 have a vulnerability in the module ngx_http_mp4_module that might allow a local attacker to cause a worker process crash, or might result in worker process memory disclosure by using a specially crafted audio or video file. The issue affects only NGINX products that are built with the module ngx_http_mp4_module, when the mp4 directive is used in the configuration file. Further, the attack is possible only if an attacker can trigger processing of a specially crafted audio or video file with the module ngx_http_mp4_module.
Affected Products: NGINX, NGINX Ingress Controller, N
Red Hat
nginx: Memory disclosure in the ngx_http_mp4_module
vendor_redhat·2022-10-19·CVSS 7.1
CVE-2022-41742 [HIGH] CWE-787 nginx: Memory disclosure in the ngx_http_mp4_module
nginx: Memory disclosure in the ngx_http_mp4_module
NGINX Open Source before versions 1.23.2 and 1.22.1, NGINX Open Source Subscription before versions R2 P1 and R1 P1, and NGINX Plus before versions R27 P1 and R26 P1 have a vulnerability in the module ngx_http_mp4_module that might allow a local attacker to cause a worker process crash, or might result in worker process memory disclosure by using a specially crafted audio or video file. The issue affects only NGINX products that are built with the module ngx_http_mp4_module, when the mp4 directive is used in the configuration file. Further, the attack is possible only if an attacker can trigger processing of a specially crafted audio or video file with the module ngx_http_mp4_module.
A vulnerability was found in NGINX’s module, ngx_http
Microsoft
NGINX ngx_http_mp4_module vulnerability CVE-2022-41742
vendor_msrc·2022-10-11·CVSS 7.1
CVE-2022-41742 [HIGH] CWE-787 NGINX ngx_http_mp4_module vulnerability CVE-2022-41742
NGINX ngx_http_mp4_module vulnerability CVE-2022-41742
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
f5: f5
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.micros
Debian
CVE-2022-41742: nginx - NGINX Open Source before versions 1.23.2 and 1.22.1, NGINX Open Source Subscript...
vendor_debian·2022·CVSS 7.1
CVE-2022-41742 [HIGH] CVE-2022-41742: nginx - NGINX Open Source before versions 1.23.2 and 1.22.1, NGINX Open Source Subscript...
NGINX Open Source before versions 1.23.2 and 1.22.1, NGINX Open Source Subscription before versions R2 P1 and R1 P1, and NGINX Plus before versions R27 P1 and R26 P1 have a vulnerability in the module ngx_http_mp4_module that might allow a local attacker to cause a worker process crash, or might result in worker process memory disclosure by using a specially crafted audio or video file. The issue affects only NGINX products that are built with the module ngx_http_mp4_module, when the mp4 directive is used in the configuration file. Further, the attack is possible only if an attacker can trigger processing of a specially crafted audio or video file with the module ngx_http_mp4_module.
Scope: local
bookworm: resolved (fixed in 1.22.1-1)
bullseye: resolved (fixed in 1.18.0-6.1+deb11u3)
forky:
OSV
nginx vulnerabilities
osv·2022-11-15·CVSS 7.8
CVE-2022-41741 [HIGH] nginx vulnerabilities
nginx vulnerabilities
It was discovered that nginx incorrectly handled certain memory operations in
the ngx_http_mp4_module module. A local attacker could possibly use this issue
with a specially crafted mp4 file to cause nginx to crash, stop responding, or
access arbitrary memory. (CVE-2022-41741, CVE-2022-41742)
GHSA
GHSA-wj45-j4gh-fm3x: NGINX Open Source before versions 1
ghsa_unreviewed·2022-10-20
CVE-2022-41742 [HIGH] CWE-787 GHSA-wj45-j4gh-fm3x: NGINX Open Source before versions 1
NGINX Open Source before versions 1.23.2 and 1.22.1, NGINX Open Source Subscription before versions R2 P1 and R1 P1, and NGINX Plus before versions R27 P1 and R26 P1 have a vulnerability in the module ngx_http_mp4_module that might allow a local attacker to cause a worker process crash, or might result in worker process memory disclosure by using a specially crafted audio or video file. The issue affects only NGINX products that are built with the module ngx_http_mp4_module, when the mp4 directive is used in the configuration file. Further, the attack is possible only if an attacker can trigger processing of a specially crafted audio or video file with the module ngx_http_mp4_module.
OSV
CVE-2022-41742: NGINX Open Source before versions 1
osv·2022-10-19·CVSS 7.1
CVE-2022-41742 [HIGH] CVE-2022-41742: NGINX Open Source before versions 1
NGINX Open Source before versions 1.23.2 and 1.22.1, NGINX Open Source Subscription before versions R2 P1 and R1 P1, and NGINX Plus before versions R27 P1 and R26 P1 have a vulnerability in the module ngx_http_mp4_module that might allow a local attacker to cause a worker process crash, or might result in worker process memory disclosure by using a specially crafted audio or video file. The issue affects only NGINX products that are built with the module ngx_http_mp4_module, when the mp4 directive is used in the configuration file. Further, the attack is possible only if an attacker can trigger processing of a specially crafted audio or video file with the module ngx_http_mp4_module.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2022-41742 nginx: Memory disclosure in the ngx_http_mp4_module
bugzilla·2022-11-10·CVSS 7.1
CVE-2022-41742 [HIGH] CVE-2022-41742 nginx: Memory disclosure in the ngx_http_mp4_module
CVE-2022-41742 nginx: Memory disclosure in the ngx_http_mp4_module
NGINX Open Source before versions 1.23.2 and 1.22.1, NGINX Open Source Subscription before versions R2 P1 and R1 P1, and NGINX Plus before versions R27 P1 and R26 P1 have a vulnerability in the module ngx_http_mp4_module that might allow a local attacker to cause a worker process crash, or might result in worker process memory disclosure by using a specially crafted audio or video file. The issue affects only NGINX products that are built with the module ngx_http_mp4_module, when the mp4 directive is used in the configuration file. Further, the attack is possible only if an attacker can trigger processing of a specially crafted audio or video file with the module ngx_http_mp4_module.
https://nginx.org/en/security_advisori
Wiz
CVE-2025-14727 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.1
CVE-2025-14727 [HIGH] CVE-2025-14727 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-14727 :
NGINX Ingress Controller (NGINX Inc) vulnerability analysis and mitigation
A vulnerability exists in NGINX Ingress Controller's nginx.org/rewrite-target annotation validation.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Source : NVD
## 8.7
Score
Published December 17, 2025
Severity HIGH
CNA Score 8.7
Affected Technologies
NGINX Ingress Controller (NGINX Inc)
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 41
Exploitation Probability (EPSS) 0.2
Affected packages and libraries
cpe:2.3:a:f5:nginx_ingress_controller
Sources
Linux Severity HIGH Has Fix Added at: Dec 18, 2025
Linux Severity HIGH Has Fix Added at: Ja
https://lists.debian.org/debian-lts-announce/2022/11/msg00031.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BPRVYA4FS34VWB4FEFYNAD7Z2LFCJVEI/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FD6M3PVVKO35WLAA7GLDBS6TEQ26SM64/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WBORRVG7VVXYOAIAD64ZHES2U2VIUKFQ/https://security.netapp.com/advisory/ntap-20230120-0005/https://support.f5.com/csp/article/K28112382https://www.debian.org/security/2022/dsa-5281https://lists.debian.org/debian-lts-announce/2022/11/msg00031.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BPRVYA4FS34VWB4FEFYNAD7Z2LFCJVEI/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FD6M3PVVKO35WLAA7GLDBS6TEQ26SM64/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WBORRVG7VVXYOAIAD64ZHES2U2VIUKFQ/https://security.netapp.com/advisory/ntap-20230120-0005/https://support.f5.com/csp/article/K28112382https://www.debian.org/security/2022/dsa-5281
2022-10-19
Published