F5 Nginx vulnerabilities
65 known vulnerabilities affecting f5/nginx.
Total CVEs
65
CISA KEV
1
actively exploited
Public exploits
11
Exploited in wild
2
Severity breakdown
CRITICAL6HIGH29MEDIUM28LOW2
Vulnerabilities
Page 2 of 4
CVE-2014-0133P3HIGHCVSS 7.5≥ 1.3.15, < 1.4.7≥ 1.5.0, ≤ 1.5.112014-03-28
CVE-2014-0133 [HIGH] CWE-787 CVE-2014-0133: Heap-based buffer overflow in the SPDY implementation in nginx 1.3.15 before 1.4.7 and 1.5.x before
Heap-based buffer overflow in the SPDY implementation in nginx 1.3.15 before 1.4.7 and 1.5.x before 1.5.12 allows remote attackers to execute arbitrary code via a crafted request.
nvdosv
CVE-2026-32647P3HIGHCVSS 8.5≥ 0, < 1.28.3-12026-03-24
CVE-2026-32647 [HIGH] CVE-2026-32647: NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module module, which might allow an attacker to trigger a buffer over-read o
NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module module, which might allow an attacker to trigger a buffer over-read or over-write to the NGINX worker memory resulting in its termination or possibly code execution, using a specially crafted MP4 file. This issue affects NGINX Ope
osv
CVE-2026-27651P3HIGHCVSS 8.7≥ 0, < 1.28.3-12026-03-24
CVE-2026-27651 [HIGH] CVE-2026-27651: When the ngx_mail_auth_http_module module is enabled on NGINX Plus or NGINX Open Source, undisclosed requests can cause worker processes to terminate
When the ngx_mail_auth_http_module module is enabled on NGINX Plus or NGINX Open Source, undisclosed requests can cause worker processes to terminate. This issue may occur when (1) CRAM-MD5 or APOP authentication is enabled, and (2) the authentication server permits retry by returning the Auth-Wait response hea
osv
CVE-2024-33452P3HIGHCVSS 7.7≥ 0, < 1.18.0-6.1+deb11u5≥ 0, < 1.22.0-32025-04-22
CVE-2024-33452 [HIGH] CVE-2024-33452: An issue in OpenResty lua-nginx-module v
An issue in OpenResty lua-nginx-module v.0.10.26 and before allows a remote attacker to conduct HTTP request smuggling via a crafted HEAD request.
osv
CVE-2018-16844P3HIGHCVSS 7.5≥ 1.9.5, < 1.14.1≥ 1.15.0, < 1.15.62018-11-07
CVE-2018-16844 [HIGH] CWE-400 CVE-2018-16844: nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can
nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive CPU usage. This issue affects nginx compiled with the ngx_http_v2_module (not compiled by default) if the 'http2' option of the 'listen' directive is used in a configuration file.
nvdosv
CVE-2021-46461P3CRITICALCVSS 9.8≥ 0, < 1.20.2-r22022-02-14
CVE-2021-46461 [CRITICAL] CVE-2021-46461: njs through 0
njs through 0.7.0, used in NGINX, was discovered to contain an out-of-bounds array access via njs_vmcode_typeof in /src/njs_vmcode.c.
osv
CVE-2016-4450P3HIGHCVSS 7.5≥ 1.3.9, < 1.10.1v1.11.02016-06-07
CVE-2016-4450 [HIGH] CWE-476 CVE-2016-4450: os/unix/ngx_files.c in nginx before 1.10.1 and 1.11.x before 1.11.1 allows remote attackers to cause
os/unix/ngx_files.c in nginx before 1.10.1 and 1.11.x before 1.11.1 allows remote attackers to cause a denial of service (NULL pointer dereference and worker process crash) via a crafted request, involving writing a client request body to a temporary file.
nvdosv
CVE-2016-0746P3CRITICALCVSS 9.8≥ 0.6.18, ≤ 1.8.0≥ 1.9.0, < 1.9.102016-02-15
CVE-2016-0746 [CRITICAL] CWE-416 CVE-2016-0746: Use-after-free vulnerability in the resolver in nginx 0.6.18 through 1.8.0 and 1.9.x before 1.9.10 a
Use-after-free vulnerability in the resolver in nginx 0.6.18 through 1.8.0 and 1.9.x before 1.9.10 allows remote attackers to cause a denial of service (worker process crash) or possibly have unspecified other impact via a crafted DNS response related to CNAME response processing.
nvdosv
CVE-2021-46463P3CRITICALCVSS 9.8≥ 0, < 1.20.2-r22022-02-14
CVE-2021-46463 [CRITICAL] CVE-2021-46463: njs through 0
njs through 0.7.1, used in NGINX, was discovered to contain a control flow hijack caused by a Type Confusion vulnerability in njs_promise_perform_then().
osv
CVE-2021-3618P3HIGHCVSS 7.4fixed in 1.21.02022-03-23
CVE-2021-3618 [HIGH] CWE-295 CVE-2021-3618: ALPACA is an application layer protocol content confusion attack, exploiting TLS servers implementin
ALPACA is an application layer protocol content confusion attack, exploiting TLS servers implementing different protocols but using compatible certificates, such as multi-domain or wildcard certificates. A MiTM attacker having access to victim's traffic at the TCP/IP layer can redirect traffic from one subdomain to another, resulting in a valid TLS sess
nvdosv
CVE-2022-41741P3HIGHCVSS 7.8≥ 1.1.3, ≤ 1.22.0≥ r22, ≤ r27+6 more2022-10-19
CVE-2022-41741 [HIGH] CWE-787 CVE-2022-41741: NGINX Open Source before versions 1.23.2 and 1.22.1, NGINX Open Source Subscription before versions
NGINX Open Source before versions 1.23.2 and 1.22.1, NGINX Open Source Subscription before versions R2 P1 and R1 P1, and NGINX Plus before versions R27 P1 and R26 P1 have a vulnerability in the module ngx_http_mp4_module that might allow a local attacker to corrupt NGINX worker memory, resulting in its termination or potential other impact using a spec
nvdosv
CVE-2020-11724P3HIGHCVSS 7.5≥ 0, < 1.10.3-0ubuntu0.16.04.5+esm3≥ 0, < 1.14.0-0ubuntu1.10+1 more2022-04-12
CVE-2020-11724 [HIGH] nginx vulnerabilities
nginx vulnerabilities
It was discovered that nginx Lua module mishandled certain inputs.
An attacker could possibly use this issue to perform an HTTP Request
Smuggling attack. This issue was fixed for Ubuntu 18.04 LTS and
Ubuntu 20.04 LTS. (CVE-2020-11724)
It was discovered that nginx Lua module mishandled certain inputs.
An attacker could possibly use this issue to disclose sensitive
information. This issue only affects Ubuntu 18.04 LTS and
Ubuntu 2
osv
CVE-2022-25139P3CRITICALCVSS 9.8≥ 0, < 1.20.2-r22022-02-14
CVE-2022-25139 [CRITICAL] CVE-2022-25139: njs through 0
njs through 0.7.0, used in NGINX, was discovered to contain a heap use-after-free in njs_await_fulfilled.
osv
CVE-2024-24989P3HIGHCVSS 7.5≥ 0, < 1.26.0-12024-02-14
CVE-2024-24989 [HIGH] CVE-2024-24989: When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed requests can cause NGINX worker processes to terminate
When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed requests can cause NGINX worker processes to terminate. Note: The HTTP/3 QUIC module is not enabled by default and is considered experimental. For more information, refer to Support for QUIC and HTTP/3 https://nginx.org/en/docs/quic.
osv
CVE-2024-24990P3HIGHCVSS 7.5≥ 0, < 1.26.0-12024-02-14
CVE-2024-24990 [HIGH] CVE-2024-24990: When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed requests can cause NGINX worker processes to terminate
When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed requests can cause NGINX worker processes to terminate. Note: The HTTP/3 QUIC module is not enabled by default and is considered experimental. For more information, refer to Support for QUIC and HTTP/3 https://nginx.org/en/docs/quic.
osv
CVE-2014-3556P3MEDIUMCVSS 6.8≥ 1.5.6, < 1.6.1≥ 1.7.0, < 1.7.42014-12-29
CVE-2014-3556 [MEDIUM] CVE-2014-3556: The STARTTLS implementation in mail/ngx_mail_smtp_handler.c in the SMTP proxy in nginx 1.5.x and 1.6
The STARTTLS implementation in mail/ngx_mail_smtp_handler.c in the SMTP proxy in nginx 1.5.x and 1.6.x before 1.6.1 and 1.7.x before 1.7.4 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted SMTP sessions by sending a cleartext command that is processed after TLS is in place, related to a "plain
nvdosv
CVE-2019-20372P3MEDIUMCVSS 5.3fixed in 1.17.72020-01-09
CVE-2019-20372 [MEDIUM] CWE-444 CVE-2019-20372: NGINX before 1.17.7, with certain error_page configurations, allows HTTP request smuggling, as demon
NGINX before 1.17.7, with certain error_page configurations, allows HTTP request smuggling, as demonstrated by the ability of an attacker to read unauthorized web pages in environments where NGINX is being fronted by a load balancer.
nvdosv
CVE-2012-2089P3MEDIUMCVSS 6.8≥ 1.0.7, ≤ 1.0.14≥ 1.1.3, ≤ 1.1.182012-04-17
CVE-2012-2089 [MEDIUM] CWE-120 CVE-2012-2089: Buffer overflow in ngx_http_mp4_module.c in the ngx_http_mp4_module module in nginx 1.0.7 through 1.
Buffer overflow in ngx_http_mp4_module.c in the ngx_http_mp4_module module in nginx 1.0.7 through 1.0.14 and 1.1.3 through 1.1.18, when the mp4 directive is used, allows remote attackers to cause a denial of service (memory overwrite) or possibly execute arbitrary code via a crafted MP4 file.
nvdosv
CVE-2026-1642P3HIGHCVSS 8.2≥ 0, < 1.22.1-9+deb12u4≥ 0, < 1.26.3-3+deb13u2+1 more2026-02-04
CVE-2026-1642 [HIGH] CVE-2026-1642: A vulnerability exists in NGINX OSS and NGINX Plus when configured to proxy to upstream Transport Layer Security (TLS) servers
A vulnerability exists in NGINX OSS and NGINX Plus when configured to proxy to upstream Transport Layer Security (TLS) servers. An attacker with a man-in-the-middle (MITM) position on the upstream server side—along with conditions beyond the attacker's control—may be able to inject plain text data into the response from an upstream pro
osv
CVE-2016-0747P3MEDIUMCVSS 5.3≥ 0.6.18, < 1.8.1≥ 1.9.0, < 1.9.102016-02-15
CVE-2016-0747 [MEDIUM] CWE-400 CVE-2016-0747: The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 does not properly limit CNAME resolution,
The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 does not properly limit CNAME resolution, which allows remote attackers to cause a denial of service (worker process resource consumption) via vectors related to arbitrary name resolution.
nvdosv