F5 nginx plus是美国F5公司的一款高性能Web服务器和反向代理。 F5 Nginx Plus存在缓冲区错误漏洞,该漏洞源于ngx_http_charset_module模块问题,当通过location块提供或代理内容时配置了source_charset utf-8和charset指令(例如charset koi8-r),远程未经身份验证的攻击者可以发送请求,导致NGINX worker进程发生堆缓冲区过度读取,造成有限的内存泄露或重启。以下版本受到影响:NGINX Open Source 1.
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| F5 | NGINX Open Source | 1.13.10< 1.31.2 |
affected |
1.30.0< 1.30.3 |
affected | ||
| F5 | NGINX Plus | 37.0< 37.0.2.1 |
affected |
R36< R36 P6 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| F5 | NGINX Open Source | 1.13.10 ~ 1.31.2 | - |
|
| F5 | NGINX Plus | 37.0 ~ 37.0.2.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-42530 | 8.1 HIGH | NGINX Open-Source ngx_http_v3_module vulnerability |
| CVE-2026-42055 | 8.1 HIGH | NGINX ngx_http_proxy_v2_module and ngx_http_grpc_module vulnerability |
| CVE-2026-11311 | 8.1 HIGH | NGINX Gateway Fabric vulnerability |
| CVE-2026-50107 | 8.1 HIGH | NGINX Gateway Fabric vulnerability |
| CVE-2026-32682 | 6.5 MEDIUM | NGINX Gateway Fabric vulnerability |
No comments yet