---
title: 'Topic: nginx'
canonical_url: https://portal.chinng-lab-srv.dev/topics/nginx.md
content_kind: topic
updated_at: '2026-07-19T06:52:16Z'
---

# Topic: nginx

> Stable topic monitoring page generated from normalized published metadata.

- Canonical: https://portal.chinng-lab-srv.dev/topics/nginx.md
- Last updated: 2026-07-19T06:52:16Z
- Search: https://portal.chinng-lab-srv.dev/api/search?q=nginx
- MCP: portal_search(q="nginx")

## Related categories

- security/os

## Related entities

- CVE
- Security Enhancement

## Latest articles

- [DEBIAN-CVE-2026-60005 — nginx](https://portal.chinng-lab-srv.dev/security/os/security-20260718-ff4471.md): NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module. When the slice directive and unnamed regex captures are configured or when a background cache update happens…
- [DEBIAN-CVE-2026-56434 — nginx](https://portal.chinng-lab-srv.dev/security/os/security-20260719-649a91.md): NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssi_module module. This vulnerability may exist when the Server-Side Includes (SSI), proxy_pass, and proxy_buffering off directiv…
- [DEBIAN-CVE-2026-42533 — nginx](https://portal.chinng-lab-srv.dev/security/os/security-20260719-3eea23.md): A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the map's regex capture variables before referencing the map out…
- [DEBIAN-CVE-2026-48142 — nginx](https://portal.chinng-lab-srv.dev/security/os/security-20260705-f7f2cd.md): NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When content is served or proxied through a location block with both source_charset utf-8; and a charset d…
- [DEBIAN-CVE-2026-42055 — nginx](https://portal.chinng-lab-srv.dev/security/os/security-20260705-fbcaf3.md): NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass directi…
- [DEBIAN-CVE-2026-9256 — nginx](https://portal.chinng-lab-srv.dev/security/os/security-20260705-865914.md): NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite directive uses a regex pattern with distinct, overlapping Perl-Co…
- [DEBIAN-CVE-2026-42946 — nginx](https://portal.chinng-lab-srv.dev/security/os/security-20260705-3b2e20.md): A vulnerability exists in the ngx_http_scgi_module and ngx_http_uwsgi_module modules that may result in excessive memory allocation or an over-read of data. When scgi_pass or uwsgi_pass is configured…
- [DEBIAN-CVE-2026-42945 — nginx](https://portal.chinng-lab-srv.dev/security/os/security-20260705-1d000e.md): NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an…
- [DEBIAN-CVE-2026-42926 — nginx](https://portal.chinng-lab-srv.dev/security/os/security-20260705-a3fcde.md): When NGINX Open Source is configured to proxy HTTP/2 traffic by setting proxy_http_version to 2, and also uses proxy_set_body, an attacker may be able to inject frame headers and payload bytes to the…
- [DEBIAN-CVE-2026-42934 — nginx](https://portal.chinng-lab-srv.dev/security/os/security-20260705-701779.md): NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When charset, source_charset, and charset_map and proxy_pass with disabled buffering ("off") directives ar…
- [DEBIAN-CVE-2026-40701 — nginx](https://portal.chinng-lab-srv.dev/security/os/security-20260705-5a5b8b.md): NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssl_module module when the ssl_verify_client directive is set to "on" or "optional," and the ssl_ocsp directive is set to "on" or…
- [DEBIAN-CVE-2026-40460 — nginx](https://portal.chinng-lab-srv.dev/security/os/security-20260705-a9b5d4.md): When NGINX Plus or NGINX Open Source are configured to use the HTTP/3 QUIC module, an attacker may be able to spoof their source IP address allowing for bypass of authorization or bypass of rate limi…
- [DEBIAN-CVE-2026-32647 — nginx](https://portal.chinng-lab-srv.dev/security/os/security-20260705-178df2.md): NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module module, which might allow an attacker to trigger a buffer over-read or over-write to the NGINX worker memory resulting…
- [DEBIAN-CVE-2026-27784 — nginx](https://portal.chinng-lab-srv.dev/security/os/security-20260705-f71e59.md): The 32-bit implementation of NGINX Open Source has a vulnerability in the ngx_http_mp4_module module, which might allow an attacker to over-read or over-write NGINX worker memory resulting in its ter…
- [DEBIAN-CVE-2026-28755 — nginx](https://portal.chinng-lab-srv.dev/security/os/security-20260705-aa44e8.md): NGINX Plus and NGINX Open Source have a vulnerability in the ngx_stream_ssl_module module due to the improper handling of revoked certificates when configured with the ssl_verify_client on and ssl_oc…
- [DEBIAN-CVE-2026-27654 — nginx](https://portal.chinng-lab-srv.dev/security/os/security-20260705-7c3ab1.md): NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_dav_module module that might allow an attacker to trigger a buffer overflow to the NGINX worker process; this vulnerability may r…
- [DEBIAN-CVE-2026-28753 — nginx](https://portal.chinng-lab-srv.dev/security/os/security-20260705-774847.md): NGINX Plus and NGINX Open Source have a vulnerability in the ngx_mail_smtp_module module due to the improper handling of CRLF sequences in DNS responses. This allows an attacker-controlled DNS server…
- [DEBIAN-CVE-2026-27651 — nginx](https://portal.chinng-lab-srv.dev/security/os/security-20260705-febd21.md): When the ngx_mail_auth_http_module module is enabled on NGINX Plus or NGINX Open Source, undisclosed requests can cause worker processes to terminate. This issue may occur when (1) CRAM-MD5 or APOP a…
- [DSA-6131-1: nginx - security update](https://portal.chinng-lab-srv.dev/security/os/security-20260705-26478d.md): nginx - security update
- [DEBIAN-CVE-2026-1642 — nginx](https://portal.chinng-lab-srv.dev/security/os/security-20260705-987a34.md): A vulnerability exists in NGINX OSS and NGINX Plus when configured to proxy to upstream Transport Layer Security (TLS) servers. An attacker with a man-in-the-middle (MITM) position on the upstream se…
- [DEBIAN-CVE-2025-53859 — nginx](https://portal.chinng-lab-srv.dev/security/os/security-20260705-c50ccf.md): NGINX Open Source and NGINX Plus have a vulnerability in the ngx_mail_smtp_module that might allow an unauthenticated attacker to over-read NGINX SMTP authentication process memory; as a result, the…
- [DEBIAN-CVE-2025-23419 — nginx](https://portal.chinng-lab-srv.dev/security/os/security-20260705-a3eae5.md): When multiple server blocks are configured to share the same IP address and port, an attacker can use session resumption to bypass client certificate authentication requirements on these servers. Thi…
- [DEBIAN-CVE-2024-7347 — nginx](https://portal.chinng-lab-srv.dev/security/os/security-20260705-dff970.md): NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module, which might allow an attacker to over-read NGINX worker memory resulting in its termination, using a specially crafte…
- [DEBIAN-CVE-2024-35200 — nginx](https://portal.chinng-lab-srv.dev/security/os/security-20260705-cdef0b.md): When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 requests can cause NGINX worker processes to terminate.
- [DEBIAN-CVE-2024-34161 — nginx](https://portal.chinng-lab-srv.dev/security/os/security-20260705-a835ce.md): When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module and the network infrastructure supports a Maximum Transmission Unit (MTU) of 4096 or greater without fragmentation, undisclos…
- [DEBIAN-CVE-2024-32760 — nginx](https://portal.chinng-lab-srv.dev/security/os/security-20260705-a3d82a.md): When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 encoder instructions can cause NGINX worker processes to terminate or cause or other potential impact.
- [DEBIAN-CVE-2024-31079 — nginx](https://portal.chinng-lab-srv.dev/security/os/security-20260705-15bcfa.md): When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 requests can cause NGINX worker processes to terminate or cause other potential impact. This attack requi…
- [DEBIAN-CVE-2024-24989 — nginx](https://portal.chinng-lab-srv.dev/security/os/security-20260705-ed2fe0.md): When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed requests can cause NGINX worker processes to terminate. Note: The HTTP/3 QUIC module is not enabled by default a…
- [DEBIAN-CVE-2024-24990 — nginx](https://portal.chinng-lab-srv.dev/security/os/security-20260705-7b345f.md): When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed requests can cause NGINX worker processes to terminate. Note: The HTTP/3 QUIC module is not enabled by default a…
- [DEBIAN-CVE-2023-44487 — nginx](https://portal.chinng-lab-srv.dev/security/os/security-20260705-1ef4a0.md): The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
- [DEBIAN-CVE-2013-0337 — nginx](https://portal.chinng-lab-srv.dev/security/os/security-20260705-49ad54.md): The default configuration of nginx, possibly 1.3.13 and earlier, uses world-readable permissions for the (1) access.log and (2) error.log files, which allows local users to obtain sensitive informati…
- [DEBIAN-CVE-2009-4487 — nginx](https://portal.chinng-lab-srv.dev/security/os/security-20260705-fe606f.md): nginx 0.7.64 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite…
