cbcvebase.

F5 Nginx vulnerabilities

65 known vulnerabilities affecting f5/nginx.

Total CVEs
65
CISA KEV
1
actively exploited
Public exploits
11
Exploited in wild
2
Severity breakdown
CRITICAL6HIGH29MEDIUM28LOW2

Vulnerabilities

Page 4 of 4
CVE-2025-53859P4MEDIUMCVSS 6.3≥ 0, < 1.28.2-r02025-08-13
CVE-2025-53859 [MEDIUM] CVE-2025-53859: NGINX Open Source and NGINX Plus have a vulnerability in the ngx_mail_smtp_module that might allow an unauthenticated attacker to over-read NGINX SMTP NGINX Open Source and NGINX Plus have a vulnerability in the ngx_mail_smtp_module that might allow an unauthenticated attacker to over-read NGINX SMTP authentication process memory; as a result, the server side may leak arbitrary bytes sent in a request to the authentication server. This issue happens during
osv
CVE-2024-7347P4MEDIUMCVSS 5.7≥ 0, < 1.18.0-6.1+deb11u4≥ 0, < 1.22.1-9+deb12u2+1 more2024-08-14
CVE-2024-7347 [MEDIUM] CVE-2024-7347: NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module, which might allow an attacker to over-read NGINX worker memory resul NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module, which might allow an attacker to over-read NGINX worker memory resulting in its termination, using a specially crafted mp4 file. The issue only affects NGINX if it is built with the ngx_http_mp4_module and the mp4 directive is us
osv
CVE-2026-28753P4MEDIUMCVSS 6.3≥ 0, < 1.28.3-12026-03-24
CVE-2026-28753 [MEDIUM] CVE-2026-28753: NGINX Plus and NGINX Open Source have a vulnerability in the ngx_mail_smtp_module module due to the improper handling of CRLF sequences in DNS respons NGINX Plus and NGINX Open Source have a vulnerability in the ngx_mail_smtp_module module due to the improper handling of CRLF sequences in DNS responses. This allows an attacker-controlled DNS server to inject arbitrary headers into SMTP upstream requests, leading to potential request manipulation. Note: Sof
osv
CVE-2012-4929P4LOWCVSS 2.6≥ 0, < 1.2.1-2.22012-09-15
CVE-2012-4929 [LOW] CVE-2012-4929: The TLS protocol 1 The TLS protocol 1.2 and earlier, as used in Mozilla Firefox, Google Chrome, Qt, and other products, can encrypt compressed data without properly obfuscating the length of the unencrypted data, which allows man-in-the-middle attackers to obtain plaintext HTTP headers by observing length differences during a series of guesses in which a string in an HTTP request potentially matches an unknown string in an HTTP header, aka a "CRIME" attack.
osv
CVE-2012-3380P4LOWCVSS 2.1≥ 0, < 1.2.1-22012-08-31
CVE-2012-3380 [LOW] CVE-2012-3380: Directory traversal vulnerability in naxsi-ui/nx_extract Directory traversal vulnerability in naxsi-ui/nx_extract.py in the Naxsi module before 0.46-1 for Nginx allows local users to read arbitrary files via unspecified vectors.
osv
F5 Nginx vulnerabilities | cvebase