Debian Nginx vulnerabilities
53 known vulnerabilities affecting debian/nginx.
Total CVEs
53
CISA KEV
1
actively exploited
Public exploits
7
Exploited in wild
2
Severity breakdown
CRITICAL2HIGH22MEDIUM15LOW14
Vulnerabilities
Page 1 of 3
CVE-2023-44487P1HIGHCVSS 7.5KEVPoCfixed in dnsdist 1.8.2-2 (forky)2023
CVE-2023-44487 [HIGH] CVE-2023-44487: dnsdist - The HTTP/2 protocol allows a denial of service (server resource consumption) bec...
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 1.8.2-2)
sid: resolved (fixed in 1.8.2-2)
trixie: resolved (fixed in 1.8.2-2)
debian
CVE-2009-3555P1MEDIUMCVSS 5.8ExploitedPoCfixed in apache2 2.2.14-2 (bookworm)2009
CVE-2009-3555 [MEDIUM] CVE-2009-3555: apache2 - The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Micr...
The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier, OpenSSL before 0.9.8l, GnuTLS 2.8.5 and earlier, Mozilla Network Security Services (NSS) 3.12.4 and earlier, multiple Cisco products, and other products, does not properly associate reneg
debian
CVE-2009-2629P2MEDIUMCVSS 7.5PoCfixed in nginx 0.7.61-3 (bookworm)2009
CVE-2009-2629 [HIGH] CVE-2009-2629: nginx - Buffer underflow in src/http/ngx_http_parse.c in nginx 0.1.0 through 0.5.37, 0.6...
Buffer underflow in src/http/ngx_http_parse.c in nginx 0.1.0 through 0.5.37, 0.6.x before 0.6.39, 0.7.x before 0.7.62, and 0.8.x before 0.8.15 allows remote attackers to execute arbitrary code via crafted HTTP requests.
Scope: local
bookworm: resolved (fixed in 0.7.61-3)
bullseye: resolved (fixed in 0.7.61-3)
forky: resolved (fixed in 0.7.61-3)
sid: resolved (fixed in 0
debian
CVE-2021-23017P2HIGHCVSS 7.7PoCfixed in nginx 1.18.0-6.1 (bookworm)2021
CVE-2021-23017 [HIGH] CVE-2021-23017: nginx - A security issue in nginx resolver was identified, which might allow an attacker...
A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cause 1-byte memory overwrite, resulting in worker process crash or potential other impact.
Scope: local
bookworm: resolved (fixed in 1.18.0-6.1)
bullseye: resolved (fixed in 1.18.0-6.1)
forky: resolved (fixed in 1.18.0-6.1)
sid: res
debian
CVE-2013-4547P2HIGHCVSS 7.5PoCfixed in nginx 1.4.4-1 (bookworm)2013
CVE-2013-4547 [HIGH] CVE-2013-4547: nginx - nginx 0.8.41 through 1.4.3 and 1.5.x before 1.5.7 allows remote attackers to byp...
nginx 0.8.41 through 1.4.3 and 1.5.x before 1.5.7 allows remote attackers to bypass intended restrictions via an unescaped space character in a URI.
Scope: local
bookworm: resolved (fixed in 1.4.4-1)
bullseye: resolved (fixed in 1.4.4-1)
forky: resolved (fixed in 1.4.4-1)
sid: resolved (fixed in 1.4.4-1)
trixie: resolved (fixed in 1.4.4-1)
debian
CVE-2016-1247P3HIGHCVSS 7.8PoCfixed in nginx 1.10.2-1 (bookworm)2016
CVE-2016-1247 [HIGH] CVE-2016-1247: nginx - The nginx package before 1.6.2-5+deb8u3 on Debian jessie, the nginx packages bef...
The nginx package before 1.6.2-5+deb8u3 on Debian jessie, the nginx packages before 1.4.6-1ubuntu3.6 on Ubuntu 14.04 LTS, before 1.10.0-0ubuntu0.16.04.3 on Ubuntu 16.04 LTS, and before 1.10.1-0ubuntu1.1 on Ubuntu 16.10, and the nginx ebuild before 1.10.2-r3 on Gentoo allow local users with access to the web server user account to gain root privileges via a symlink attac
debian
CVE-2019-9513P3HIGHCVSS 7.5fixed in nghttp2 1.39.2-1 (bookworm)2019
CVE-2019-9513 [HIGH] CVE-2019-9513: nghttp2 - Some HTTP/2 implementations are vulnerable to resource loops, potentially leadin...
Some HTTP/2 implementations are vulnerable to resource loops, potentially leading to a denial of service. The attacker creates multiple request streams and continually shuffles the priority of the streams in a way that causes substantial churn to the priority tree. This can consume excess CPU.
Scope: local
bookworm: resolved (fixed in 1.39.2-1)
bullseye: resolved (fix
debian
CVE-2026-27654P2HIGHCVSS 8.8fixed in nginx 1.28.3-1 (forky)2026
CVE-2026-27654 [HIGH] CVE-2026-27654: nginx - NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_dav_module...
NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_dav_module module that might allow an attacker to trigger a buffer overflow to the NGINX worker process; this vulnerability may result in termination of the NGINX worker process or modification of source or destination file names outside the document root. This issue affects NGINX Open Source and NG
debian
CVE-2017-7529P2HIGHCVSS 7.5fixed in nginx 1.13.3-1 (bookworm)2017
CVE-2017-7529 [HIGH] CVE-2017-7529: nginx - Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable to integer ...
Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable to integer overflow vulnerability in nginx range filter module resulting into leak of potentially sensitive information triggered by specially crafted request.
Scope: local
bookworm: resolved (fixed in 1.13.3-1)
bullseye: resolved (fixed in 1.13.3-1)
forky: resolved (fixed in 1.13.3-1)
sid: resolved (f
debian
CVE-2019-9511P3HIGHCVSS 7.5fixed in nghttp2 1.39.2-1 (bookworm)2019
CVE-2019-9511 [HIGH] CVE-2019-9511: nghttp2 - Some HTTP/2 implementations are vulnerable to window size manipulation and strea...
Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of service. The attacker requests a large amount of data from a specified resource over multiple streams. They manipulate window size and stream priority to force the server to queue the data in 1-byte chunks. Depending on how
debian
CVE-2016-0742P3HIGHCVSS 7.5fixed in nginx 1.9.10-1 (bookworm)2016
CVE-2016-0742 [HIGH] CVE-2016-0742: nginx - The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 allows remote attacke...
The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 allows remote attackers to cause a denial of service (invalid pointer dereference and worker process crash) via a crafted UDP DNS response.
Scope: local
bookworm: resolved (fixed in 1.9.10-1)
bullseye: resolved (fixed in 1.9.10-1)
forky: resolved (fixed in 1.9.10-1)
sid: resolved (fixed in 1.9.10-1)
trixie: reso
debian
CVE-2009-3898P3LOWCVSS 4.9PoCfixed in nginx 0.7.63-1 (bookworm)2009
CVE-2009-3898 [MEDIUM] CVE-2009-3898: nginx - Directory traversal vulnerability in src/http/modules/ngx_http_dav_module.c in n...
Directory traversal vulnerability in src/http/modules/ngx_http_dav_module.c in nginx (aka Engine X) before 0.7.63, and 0.8.x before 0.8.17, allows remote authenticated users to create or overwrite arbitrary files via a .. (dot dot) in the Destination HTTP header for the WebDAV (1) COPY or (2) MOVE method.
Scope: local
bookworm: resolved (fixed in 0.7.63-1)
bullseye: r
debian
CVE-2018-16843P3HIGHCVSS 7.5fixed in nginx 1.14.1-1 (bookworm)2018
CVE-2018-16843 [HIGH] CVE-2018-16843: nginx - nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementatio...
nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive memory consumption. This issue affects nginx compiled with the ngx_http_v2_module (not compiled by default) if the 'http2' option of the 'listen' directive is used in a configuration file.
Scope: local
bookworm: resolved (fixed in 1.14.1-1)
bullseye
debian
CVE-2019-9516P3MEDIUMCVSS 6.5fixed in nginx 1.14.2-3 (bookworm)2019
CVE-2019-9516 [MEDIUM] CVE-2019-9516: nginx - Some HTTP/2 implementations are vulnerable to a header leak, potentially leading...
Some HTTP/2 implementations are vulnerable to a header leak, potentially leading to a denial of service. The attacker sends a stream of headers with a 0-length header name and 0-length header value, optionally Huffman encoded into 1-byte or greater headers. Some implementations allocate memory for these headers and keep the allocation alive until the session dies. Thi
debian
CVE-2017-20005P3CRITICALCVSS 9.8fixed in nginx 1.13.6-1 (bookworm)2017
CVE-2017-20005 [CRITICAL] CVE-2017-20005: nginx - NGINX before 1.13.6 has a buffer overflow for years that exceed four digits, as ...
NGINX before 1.13.6 has a buffer overflow for years that exceed four digits, as demonstrated by a file with a modification date in 1969 that causes an integer overflow (or a false modification date far in the future), when encountered by the autoindex module.
Scope: local
bookworm: resolved (fixed in 1.13.6-1)
bullseye: resolved (fixed in 1.13.6-1)
forky: resolved
debian
CVE-2014-0133P3LOWCVSS 7.5fixed in nginx 1.4.7-1 (bookworm)2014
CVE-2014-0133 [HIGH] CVE-2014-0133: nginx - Heap-based buffer overflow in the SPDY implementation in nginx 1.3.15 before 1.4...
Heap-based buffer overflow in the SPDY implementation in nginx 1.3.15 before 1.4.7 and 1.5.x before 1.5.12 allows remote attackers to execute arbitrary code via a crafted request.
Scope: local
bookworm: resolved (fixed in 1.4.7-1)
bullseye: resolved (fixed in 1.4.7-1)
forky: resolved (fixed in 1.4.7-1)
sid: resolved (fixed in 1.4.7-1)
trixie: resolved (fixed in 1.4.7-1)
debian
CVE-2026-32647P3HIGHCVSS 8.5fixed in nginx 1.28.3-1 (forky)2026
CVE-2026-32647 [HIGH] CVE-2026-32647: nginx - NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module...
NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module module, which might allow an attacker to trigger a buffer over-read or over-write to the NGINX worker memory resulting in its termination or possibly code execution, using a specially crafted MP4 file. This issue affects NGINX Open Source and NGINX Plus if it is built with the ngx_http_mp
debian
CVE-2026-27651P3HIGHCVSS 8.7fixed in nginx 1.28.3-1 (forky)2026
CVE-2026-27651 [HIGH] CVE-2026-27651: nginx - When the ngx_mail_auth_http_module module is enabled on NGINX Plus or NGINX Open...
When the ngx_mail_auth_http_module module is enabled on NGINX Plus or NGINX Open Source, undisclosed requests can cause worker processes to terminate. This issue may occur when (1) CRAM-MD5 or APOP authentication is enabled, and (2) the authentication server permits retry by returning the Auth-Wait response header. Note: Software versions which have reached End of Tec
debian
CVE-2024-33452P3HIGHCVSS 7.7fixed in libnginx-mod-http-lua 1:0.10.23-1+deb12u1 (bookworm)2024
CVE-2024-33452 [HIGH] CVE-2024-33452: libnginx-mod-http-lua - An issue in OpenResty lua-nginx-module v.0.10.26 and before allows a remote atta...
An issue in OpenResty lua-nginx-module v.0.10.26 and before allows a remote attacker to conduct HTTP request smuggling via a crafted HEAD request.
Scope: local
bookworm: resolved (fixed in 1:0.10.23-1+deb12u1)
forky: resolved (fixed in 1:0.10.27-1)
sid: resolved (fixed in 1:0.10.27-1)
trixie: resolved (fixed in 1:0.10.27-1)
debian
CVE-2018-16844P3HIGHCVSS 7.5fixed in nginx 1.14.1-1 (bookworm)2018
CVE-2018-16844 [HIGH] CVE-2018-16844: nginx - nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementatio...
nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive CPU usage. This issue affects nginx compiled with the ngx_http_v2_module (not compiled by default) if the 'http2' option of the 'listen' directive is used in a configuration file.
Scope: local
bookworm: resolved (fixed in 1.14.1-1)
bullseye: resolve
debian
1 / 3Next →