Debian Nginx vulnerabilities
53 known vulnerabilities affecting debian/nginx.
Total CVEs
53
CISA KEV
1
actively exploited
Public exploits
7
Exploited in wild
2
Severity breakdown
CRITICAL2HIGH22MEDIUM15LOW14
Vulnerabilities
Page 2 of 3
CVE-2016-4450P3HIGHCVSS 7.5fixed in nginx 1.10.1-1 (bookworm)2016
CVE-2016-4450 [HIGH] CVE-2016-4450: nginx - os/unix/ngx_files.c in nginx before 1.10.1 and 1.11.x before 1.11.1 allows remot...
os/unix/ngx_files.c in nginx before 1.10.1 and 1.11.x before 1.11.1 allows remote attackers to cause a denial of service (NULL pointer dereference and worker process crash) via a crafted request, involving writing a client request body to a temporary file.
Scope: local
bookworm: resolved (fixed in 1.10.1-1)
bullseye: resolved (fixed in 1.10.1-1)
forky: resolved (fixed i
debian
CVE-2016-0746P3CRITICALCVSS 9.8fixed in nginx 1.9.10-1 (bookworm)2016
CVE-2016-0746 [CRITICAL] CVE-2016-0746: nginx - Use-after-free vulnerability in the resolver in nginx 0.6.18 through 1.8.0 and 1...
Use-after-free vulnerability in the resolver in nginx 0.6.18 through 1.8.0 and 1.9.x before 1.9.10 allows remote attackers to cause a denial of service (worker process crash) or possibly have unspecified other impact via a crafted DNS response related to CNAME response processing.
Scope: local
bookworm: resolved (fixed in 1.9.10-1)
bullseye: resolved (fixed in 1.9.1
debian
CVE-2021-3618P3HIGHCVSS 7.4fixed in nginx 1.20.2-2 (bookworm)2021
CVE-2021-3618 [HIGH] CVE-2021-3618: nginx - ALPACA is an application layer protocol content confusion attack, exploiting TLS...
ALPACA is an application layer protocol content confusion attack, exploiting TLS servers implementing different protocols but using compatible certificates, such as multi-domain or wildcard certificates. A MiTM attacker having access to victim's traffic at the TCP/IP layer can redirect traffic from one subdomain to another, resulting in a valid TLS session. This breaks
debian
CVE-2022-41741P3HIGHCVSS 7.0fixed in nginx 1.22.1-1 (bookworm)2022
CVE-2022-41741 [HIGH] CVE-2022-41741: nginx - NGINX Open Source before versions 1.23.2 and 1.22.1, NGINX Open Source Subscript...
NGINX Open Source before versions 1.23.2 and 1.22.1, NGINX Open Source Subscription before versions R2 P1 and R1 P1, and NGINX Plus before versions R27 P1 and R26 P1 have a vulnerability in the module ngx_http_mp4_module that might allow a local attacker to corrupt NGINX worker memory, resulting in its termination or potential other impact using a specially crafted au
debian
CVE-2020-11724P3HIGHCVSS 7.5fixed in nginx 1.18.0-5 (bookworm)2020
CVE-2020-11724 [HIGH] CVE-2020-11724: nginx - An issue was discovered in OpenResty before 1.15.8.4. ngx_http_lua_subrequest.c ...
An issue was discovered in OpenResty before 1.15.8.4. ngx_http_lua_subrequest.c allows HTTP request smuggling, as demonstrated by the ngx.location.capture API.
Scope: local
bookworm: resolved (fixed in 1.18.0-5)
bullseye: resolved (fixed in 1.18.0-5)
forky: resolved (fixed in 1.18.0-5)
sid: resolved (fixed in 1.18.0-5)
trixie: resolved (fixed in 1.18.0-5)
debian
CVE-2024-24989P3LOWCVSS 7.5fixed in nginx 1.26.0-1 (forky)2024
CVE-2024-24989 [HIGH] CVE-2024-24989: nginx - When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undis...
When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed requests can cause NGINX worker processes to terminate. Note: The HTTP/3 QUIC module is not enabled by default and is considered experimental. For more information, refer to Support for QUIC and HTTP/3 https://nginx.org/en/docs/quic.html . NOTE: Software versions which have reached
debian
CVE-2024-24990P3LOWCVSS 7.5fixed in nginx 1.26.0-1 (forky)2024
CVE-2024-24990 [HIGH] CVE-2024-24990: nginx - When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undis...
When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed requests can cause NGINX worker processes to terminate. Note: The HTTP/3 QUIC module is not enabled by default and is considered experimental. For more information, refer to Support for QUIC and HTTP/3 https://nginx.org/en/docs/quic.html . Note: Software versions which have reached
debian
CVE-2014-3556P3MEDIUMCVSS 6.8fixed in nginx 1.6.1-1 (bookworm)2014
CVE-2014-3556 [MEDIUM] CVE-2014-3556: nginx - The STARTTLS implementation in mail/ngx_mail_smtp_handler.c in the SMTP proxy in...
The STARTTLS implementation in mail/ngx_mail_smtp_handler.c in the SMTP proxy in nginx 1.5.x and 1.6.x before 1.6.1 and 1.7.x before 1.7.4 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted SMTP sessions by sending a cleartext command that is processed after TLS is in place, related to a "plaintext comm
debian
CVE-2019-20372P3LOWCVSS 5.3fixed in nginx 1.16.1-3 (bookworm)2019
CVE-2019-20372 [MEDIUM] CVE-2019-20372: nginx - NGINX before 1.17.7, with certain error_page configurations, allows HTTP request...
NGINX before 1.17.7, with certain error_page configurations, allows HTTP request smuggling, as demonstrated by the ability of an attacker to read unauthorized web pages in environments where NGINX is being fronted by a load balancer.
Scope: local
bookworm: resolved (fixed in 1.16.1-3)
bullseye: resolved (fixed in 1.16.1-3)
forky: resolved (fixed in 1.16.1-3)
sid: re
debian
CVE-2012-2089P3MEDIUMCVSS 6.8fixed in nginx 1.1.19-1 (bookworm)2012
CVE-2012-2089 [MEDIUM] CVE-2012-2089: nginx - Buffer overflow in ngx_http_mp4_module.c in the ngx_http_mp4_module module in ng...
Buffer overflow in ngx_http_mp4_module.c in the ngx_http_mp4_module module in nginx 1.0.7 through 1.0.14 and 1.1.3 through 1.1.18, when the mp4 directive is used, allows remote attackers to cause a denial of service (memory overwrite) or possibly execute arbitrary code via a crafted MP4 file.
Scope: local
bookworm: resolved (fixed in 1.1.19-1)
bullseye: resolved (fixe
debian
CVE-2026-1642P3HIGHCVSS 8.2fixed in nginx 1.22.1-9+deb12u4 (bookworm)2026
CVE-2026-1642 [HIGH] CVE-2026-1642: nginx - A vulnerability exists in NGINX OSS and NGINX Plus when configured to proxy to u...
A vulnerability exists in NGINX OSS and NGINX Plus when configured to proxy to upstream Transport Layer Security (TLS) servers. An attacker with a man-in-the-middle (MITM) position on the upstream server side—along with conditions beyond the attacker's control—may be able to inject plain text data into the response from an upstream proxied server. Note: Software version
debian
CVE-2016-0747P3MEDIUMCVSS 5.3fixed in nginx 1.9.10-1 (bookworm)2016
CVE-2016-0747 [MEDIUM] CVE-2016-0747: nginx - The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 does not properly lim...
The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 does not properly limit CNAME resolution, which allows remote attackers to cause a denial of service (worker process resource consumption) via vectors related to arbitrary name resolution.
Scope: local
bookworm: resolved (fixed in 1.9.10-1)
bullseye: resolved (fixed in 1.9.10-1)
forky: resolved (fixed in 1.9.1
debian
CVE-2018-16845P4MEDIUMCVSS 6.1fixed in nginx 1.14.1-1 (bookworm)2018
CVE-2018-16845 [MEDIUM] CVE-2018-16845: nginx - nginx before versions 1.15.6, 1.14.1 has a vulnerability in the ngx_http_mp4_mod...
nginx before versions 1.15.6, 1.14.1 has a vulnerability in the ngx_http_mp4_module, which might allow an attacker to cause infinite loop in a worker process, cause a worker process crash, or might result in worker process memory disclosure by using a specially crafted mp4 file. The issue only affects nginx if it is built with the ngx_http_mp4_module (the module is
debian
CVE-2024-32760P4LOWCVSS 6.5fixed in nginx 1.26.0-2 (forky)2024
CVE-2024-32760 [MEDIUM] CVE-2024-32760: nginx - When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undis...
When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 encoder instructions can cause NGINX worker processes to terminate or cause or other potential impact.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 1.26.0-2)
sid: resolved (fixed in 1.26.0-2)
trixie: resolved (fixed in 1.26.0-2)
debian
CVE-2013-2070P4HIGHCVSS 7.5fixed in nginx 1.4.1-1 (bookworm)2013
CVE-2013-2070 [HIGH] CVE-2013-2070: nginx - http/modules/ngx_http_proxy_module.c in nginx 1.1.4 through 1.2.8 and 1.3.0 thro...
http/modules/ngx_http_proxy_module.c in nginx 1.1.4 through 1.2.8 and 1.3.0 through 1.4.0, when proxy_pass is used with untrusted HTTP servers, allows remote attackers to cause a denial of service (crash) and obtain sensitive information from worker process memory via a crafted proxy response, a similar vulnerability to CVE-2013-2028.
Scope: local
bookworm: resolved (fi
debian
CVE-2011-4315P4LOWCVSS 6.8fixed in nginx 1.1.8-1 (bookworm)2011
CVE-2011-4315 [MEDIUM] CVE-2011-4315: nginx - Heap-based buffer overflow in compression-pointer processing in core/ngx_resolve...
Heap-based buffer overflow in compression-pointer processing in core/ngx_resolver.c in nginx before 1.0.10 allows remote resolvers to cause a denial of service (daemon crash) or possibly have unspecified other impact via a long response.
Scope: local
bookworm: resolved (fixed in 1.1.8-1)
bullseye: resolved (fixed in 1.1.8-1)
forky: resolved (fixed in 1.1.8-1)
sid: res
debian
CVE-2022-41742P4HIGHCVSS 7.1fixed in nginx 1.22.1-1 (bookworm)2022
CVE-2022-41742 [HIGH] CVE-2022-41742: nginx - NGINX Open Source before versions 1.23.2 and 1.22.1, NGINX Open Source Subscript...
NGINX Open Source before versions 1.23.2 and 1.22.1, NGINX Open Source Subscription before versions R2 P1 and R1 P1, and NGINX Plus before versions R27 P1 and R26 P1 have a vulnerability in the module ngx_http_mp4_module that might allow a local attacker to cause a worker process crash, or might result in worker process memory disclosure by using a specially crafted a
debian
CVE-2026-27784P4HIGHCVSS 8.5fixed in nginx 1.28.3-1 (forky)2026
CVE-2026-27784 [HIGH] CVE-2026-27784: nginx - The 32-bit implementation of NGINX Open Source has a vulnerability in the ngx_ht...
The 32-bit implementation of NGINX Open Source has a vulnerability in the ngx_http_mp4_module module, which might allow an attacker to over-read or over-write NGINX worker memory resulting in its termination, using a specially crafted MP4 file. The issue only affects 32-bit NGINX Open Source if it is built with the ngx_http_mp4_module module and the mp4 directive is u
debian
CVE-2012-1180P4MEDIUMCVSS 5.0fixed in nginx 1.1.17-1 (bookworm)2012
CVE-2012-1180 [MEDIUM] CVE-2012-1180: nginx - Use-after-free vulnerability in nginx before 1.0.14 and 1.1.x before 1.1.17 allo...
Use-after-free vulnerability in nginx before 1.0.14 and 1.1.x before 1.1.17 allows remote HTTP servers to obtain sensitive information from process memory via a crafted backend response, in conjunction with a client request.
Scope: local
bookworm: resolved (fixed in 1.1.17-1)
bullseye: resolved (fixed in 1.1.17-1)
forky: resolved (fixed in 1.1.17-1)
sid: resolved (fix
debian
CVE-2020-36309P4LOWCVSS 5.3fixed in nginx 1.22.0-3 (bookworm)2020
CVE-2020-36309 [MEDIUM] CVE-2020-36309: libnginx-mod-http-lua - ngx_http_lua_module (aka lua-nginx-module) before 0.10.16 in OpenResty allows un...
ngx_http_lua_module (aka lua-nginx-module) before 0.10.16 in OpenResty allows unsafe characters in an argument when using the API to mutate a URI, or a request or response header.
Scope: local
bookworm: resolved
forky: resolved
sid: resolved
trixie: resolved
debian