Debian Nginx vulnerabilities
61 known vulnerabilities affecting debian/nginx.
Total CVEs
61
CISA KEV
1
actively exploited
Public exploits
11
Exploited in wild
1
Severity breakdown
CRITICAL2HIGH22MEDIUM15LOW22
Vulnerabilities
Page 2 of 4
CVE-2022-41742HIGHCVSS 7.1fixed in nginx 1.22.1-1 (bookworm)2022
CVE-2022-41742 [HIGH] CVE-2022-41742: nginx - NGINX Open Source before versions 1.23.2 and 1.22.1, NGINX Open Source Subscript...
NGINX Open Source before versions 1.23.2 and 1.22.1, NGINX Open Source Subscription before versions R2 P1 and R1 P1, and NGINX Plus before versions R27 P1 and R26 P1 have a vulnerability in the module ngx_http_mp4_module that might allow a local attacker to cause a worker process crash, or might result in worker process memory disclosure by using a specially crafted a
debian
CVE-2021-3618HIGHCVSS 7.4fixed in nginx 1.20.2-2 (bookworm)2021
CVE-2021-3618 [HIGH] CVE-2021-3618: nginx - ALPACA is an application layer protocol content confusion attack, exploiting TLS...
ALPACA is an application layer protocol content confusion attack, exploiting TLS servers implementing different protocols but using compatible certificates, such as multi-domain or wildcard certificates. A MiTM attacker having access to victim's traffic at the TCP/IP layer can redirect traffic from one subdomain to another, resulting in a valid TLS session. This breaks
debian
CVE-2021-23017HIGHCVSS 7.7PoCfixed in nginx 1.18.0-6.1 (bookworm)2021
CVE-2021-23017 [HIGH] CVE-2021-23017: nginx - A security issue in nginx resolver was identified, which might allow an attacker...
A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cause 1-byte memory overwrite, resulting in worker process crash or potential other impact.
Scope: local
bookworm: resolved (fixed in 1.18.0-6.1)
bullseye: resolved (fixed in 1.18.0-6.1)
forky: resolved (fixed in 1.18.0-6.1)
sid: res
debian
CVE-2020-11724HIGHCVSS 7.5fixed in nginx 1.18.0-5 (bookworm)2020
CVE-2020-11724 [HIGH] CVE-2020-11724: nginx - An issue was discovered in OpenResty before 1.15.8.4. ngx_http_lua_subrequest.c ...
An issue was discovered in OpenResty before 1.15.8.4. ngx_http_lua_subrequest.c allows HTTP request smuggling, as demonstrated by the ngx.location.capture API.
Scope: local
bookworm: resolved (fixed in 1.18.0-5)
bullseye: resolved (fixed in 1.18.0-5)
forky: resolved (fixed in 1.18.0-5)
sid: resolved (fixed in 1.18.0-5)
trixie: resolved (fixed in 1.18.0-5)
debian
CVE-2020-36309LOWCVSS 5.3fixed in nginx 1.22.0-3 (bookworm)2020
CVE-2020-36309 [MEDIUM] CVE-2020-36309: libnginx-mod-http-lua - ngx_http_lua_module (aka lua-nginx-module) before 0.10.16 in OpenResty allows un...
ngx_http_lua_module (aka lua-nginx-module) before 0.10.16 in OpenResty allows unsafe characters in an argument when using the API to mutate a URI, or a request or response header.
Scope: local
bookworm: resolved
forky: resolved
sid: resolved
trixie: resolved
debian
CVE-2019-9511HIGHCVSS 7.5fixed in nghttp2 1.39.2-1 (bookworm)2019
CVE-2019-9511 [HIGH] CVE-2019-9511: nghttp2 - Some HTTP/2 implementations are vulnerable to window size manipulation and strea...
Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of service. The attacker requests a large amount of data from a specified resource over multiple streams. They manipulate window size and stream priority to force the server to queue the data in 1-byte chunks. Depending on how
debian
CVE-2019-9513HIGHCVSS 7.5fixed in nghttp2 1.39.2-1 (bookworm)2019
CVE-2019-9513 [HIGH] CVE-2019-9513: nghttp2 - Some HTTP/2 implementations are vulnerable to resource loops, potentially leadin...
Some HTTP/2 implementations are vulnerable to resource loops, potentially leading to a denial of service. The attacker creates multiple request streams and continually shuffles the priority of the streams in a way that causes substantial churn to the priority tree. This can consume excess CPU.
Scope: local
bookworm: resolved (fixed in 1.39.2-1)
bullseye: resolved (fix
debian
CVE-2019-9516MEDIUMCVSS 6.5fixed in nginx 1.14.2-3 (bookworm)2019
CVE-2019-9516 [MEDIUM] CVE-2019-9516: nginx - Some HTTP/2 implementations are vulnerable to a header leak, potentially leading...
Some HTTP/2 implementations are vulnerable to a header leak, potentially leading to a denial of service. The attacker sends a stream of headers with a 0-length header name and 0-length header value, optionally Huffman encoded into 1-byte or greater headers. Some implementations allocate memory for these headers and keep the allocation alive until the session dies. Thi
debian
CVE-2019-20372LOWCVSS 5.3fixed in nginx 1.16.1-3 (bookworm)2019
CVE-2019-20372 [MEDIUM] CVE-2019-20372: nginx - NGINX before 1.17.7, with certain error_page configurations, allows HTTP request...
NGINX before 1.17.7, with certain error_page configurations, allows HTTP request smuggling, as demonstrated by the ability of an attacker to read unauthorized web pages in environments where NGINX is being fronted by a load balancer.
Scope: local
bookworm: resolved (fixed in 1.16.1-3)
bullseye: resolved (fixed in 1.16.1-3)
forky: resolved (fixed in 1.16.1-3)
sid: re
debian
CVE-2018-16844HIGHCVSS 7.5fixed in nginx 1.14.1-1 (bookworm)2018
CVE-2018-16844 [HIGH] CVE-2018-16844: nginx - nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementatio...
nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive CPU usage. This issue affects nginx compiled with the ngx_http_v2_module (not compiled by default) if the 'http2' option of the 'listen' directive is used in a configuration file.
Scope: local
bookworm: resolved (fixed in 1.14.1-1)
bullseye: resolve
debian
CVE-2018-16843HIGHCVSS 7.5fixed in nginx 1.14.1-1 (bookworm)2018
CVE-2018-16843 [HIGH] CVE-2018-16843: nginx - nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementatio...
nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive memory consumption. This issue affects nginx compiled with the ngx_http_v2_module (not compiled by default) if the 'http2' option of the 'listen' directive is used in a configuration file.
Scope: local
bookworm: resolved (fixed in 1.14.1-1)
bullseye
debian
CVE-2018-16845MEDIUMCVSS 6.1fixed in nginx 1.14.1-1 (bookworm)2018
CVE-2018-16845 [MEDIUM] CVE-2018-16845: nginx - nginx before versions 1.15.6, 1.14.1 has a vulnerability in the ngx_http_mp4_mod...
nginx before versions 1.15.6, 1.14.1 has a vulnerability in the ngx_http_mp4_module, which might allow an attacker to cause infinite loop in a worker process, cause a worker process crash, or might result in worker process memory disclosure by using a specially crafted mp4 file. The issue only affects nginx if it is built with the ngx_http_mp4_module (the module is
debian
CVE-2017-20005CRITICALCVSS 9.8fixed in nginx 1.13.6-1 (bookworm)2017
CVE-2017-20005 [CRITICAL] CVE-2017-20005: nginx - NGINX before 1.13.6 has a buffer overflow for years that exceed four digits, as ...
NGINX before 1.13.6 has a buffer overflow for years that exceed four digits, as demonstrated by a file with a modification date in 1969 that causes an integer overflow (or a false modification date far in the future), when encountered by the autoindex module.
Scope: local
bookworm: resolved (fixed in 1.13.6-1)
bullseye: resolved (fixed in 1.13.6-1)
forky: resolved
debian
CVE-2017-7529HIGHCVSS 7.5fixed in nginx 1.13.3-1 (bookworm)2017
CVE-2017-7529 [HIGH] CVE-2017-7529: nginx - Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable to integer ...
Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable to integer overflow vulnerability in nginx range filter module resulting into leak of potentially sensitive information triggered by specially crafted request.
Scope: local
bookworm: resolved (fixed in 1.13.3-1)
bullseye: resolved (fixed in 1.13.3-1)
forky: resolved (fixed in 1.13.3-1)
sid: resolved (f
debian
CVE-2016-0746CRITICALCVSS 9.8fixed in nginx 1.9.10-1 (bookworm)2016
CVE-2016-0746 [CRITICAL] CVE-2016-0746: nginx - Use-after-free vulnerability in the resolver in nginx 0.6.18 through 1.8.0 and 1...
Use-after-free vulnerability in the resolver in nginx 0.6.18 through 1.8.0 and 1.9.x before 1.9.10 allows remote attackers to cause a denial of service (worker process crash) or possibly have unspecified other impact via a crafted DNS response related to CNAME response processing.
Scope: local
bookworm: resolved (fixed in 1.9.10-1)
bullseye: resolved (fixed in 1.9.1
debian
CVE-2016-1247HIGHCVSS 7.8PoCfixed in nginx 1.10.2-1 (bookworm)2016
CVE-2016-1247 [HIGH] CVE-2016-1247: nginx - The nginx package before 1.6.2-5+deb8u3 on Debian jessie, the nginx packages bef...
The nginx package before 1.6.2-5+deb8u3 on Debian jessie, the nginx packages before 1.4.6-1ubuntu3.6 on Ubuntu 14.04 LTS, before 1.10.0-0ubuntu0.16.04.3 on Ubuntu 16.04 LTS, and before 1.10.1-0ubuntu1.1 on Ubuntu 16.10, and the nginx ebuild before 1.10.2-r3 on Gentoo allow local users with access to the web server user account to gain root privileges via a symlink attac
debian
CVE-2016-0742HIGHCVSS 7.5fixed in nginx 1.9.10-1 (bookworm)2016
CVE-2016-0742 [HIGH] CVE-2016-0742: nginx - The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 allows remote attacke...
The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 allows remote attackers to cause a denial of service (invalid pointer dereference and worker process crash) via a crafted UDP DNS response.
Scope: local
bookworm: resolved (fixed in 1.9.10-1)
bullseye: resolved (fixed in 1.9.10-1)
forky: resolved (fixed in 1.9.10-1)
sid: resolved (fixed in 1.9.10-1)
trixie: reso
debian
CVE-2016-4450HIGHCVSS 7.5fixed in nginx 1.10.1-1 (bookworm)2016
CVE-2016-4450 [HIGH] CVE-2016-4450: nginx - os/unix/ngx_files.c in nginx before 1.10.1 and 1.11.x before 1.11.1 allows remot...
os/unix/ngx_files.c in nginx before 1.10.1 and 1.11.x before 1.11.1 allows remote attackers to cause a denial of service (NULL pointer dereference and worker process crash) via a crafted request, involving writing a client request body to a temporary file.
Scope: local
bookworm: resolved (fixed in 1.10.1-1)
bullseye: resolved (fixed in 1.10.1-1)
forky: resolved (fixed i
debian
CVE-2016-0747MEDIUMCVSS 5.3fixed in nginx 1.9.10-1 (bookworm)2016
CVE-2016-0747 [MEDIUM] CVE-2016-0747: nginx - The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 does not properly lim...
The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 does not properly limit CNAME resolution, which allows remote attackers to cause a denial of service (worker process resource consumption) via vectors related to arbitrary name resolution.
Scope: local
bookworm: resolved (fixed in 1.9.10-1)
bullseye: resolved (fixed in 1.9.10-1)
forky: resolved (fixed in 1.9.1
debian
CVE-2014-3616MEDIUMCVSS 4.3fixed in nginx 1.6.2-1 (bookworm)2014
CVE-2014-3616 [MEDIUM] CVE-2014-3616: nginx - nginx 0.5.6 through 1.7.4, when using the same shared ssl_session_cache or ssl_s...
nginx 0.5.6 through 1.7.4, when using the same shared ssl_session_cache or ssl_session_ticket_key for multiple servers, can reuse a cached SSL session for an unrelated context, which allows remote attackers with certain privileges to conduct "virtual host confusion" attacks.
Scope: local
bookworm: resolved (fixed in 1.6.2-1)
bullseye: resolved (fixed in 1.6.2-1)
forky
debian