F5 NGINX Plus和F5 NGINX Open Source都是美国F5公司的产品。F5 NGINX Plus是一个基于软件的应用程序交付平台。F5 NGINX Open Source是一个高性能Web服务器、反向代理服务器、负载均衡器和API网关。 F5 NGINX Plus和F5 NGINX Open Source存在安全漏洞,该漏洞源于ngx_http_dav_module模块存在缓冲区溢出,可能导致工作进程终止或修改文档根目录之外的文件名。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| F5 | NGINX Open Source | 1.29.0< 1.29.7 |
affected |
0.5.13< 1.28.3 |
affected | ||
| F5 | NGINX Plus | R36< R36 P3 |
affected |
R35< R35 P2 |
affected | ||
R34< * |
affected | ||
R33< * |
affected | ||
R32< R32 P5 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| F5 | NGINX Open Source | 1.29.0 ~ 1.29.7 | - |
|
| F5 | NGINX Plus | R36 ~ R36 P3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-27784 | 7.8 HIGH | NGINX ngx_http_mp4_module vulnerability |
| CVE-2026-32647 | 7.8 HIGH | NGINX ngx_http_mp4_module vulnerability |
| CVE-2026-27651 | 7.5 HIGH | NGINX ngx_mail_auth_http_module vulnerability |
| CVE-2026-28755 | 5.4 MEDIUM | NGINX ngx_stream_ssl_module vulnerability |
| CVE-2026-28753 | 3.7 LOW | NGINX ngx_mail_proxy_module vulnerability |
No comments yet