F5
F5 Nginx: vulnerabilities and CVEs
F5 Nginx has 41 published vulnerabilities, 0 of them in the last 12 months. 3 are rated critical and 1 are listed by CISA as actively exploited.
CVEs41
Last 12 months0
Critical3
Actively exploited1
All vulnerabilities in the catalogue →⭐ Follow this technology
🔴 Actively exploited (CISA KEV)
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-44487 | High (7.5) | 100% | ⚠ Active exploitation | Oct 10, 2023 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. |
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-23419 | Medium (5.3) | 2.8% | — | Feb 5, 2025 | When multiple server blocks are configured to share the same IP address and port, an attacker can use session resumption to bypass client certificate authentication requirements on these servers. This vulnerability… |
| CVE-2023-44487 | High (7.5) | 100% | ⚠ Active exploitation | Oct 10, 2023 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. |
| CVE-2022-41742 | High (7.1) | 1.1% | — | Oct 19, 2022 | NGINX Open Source before versions 1.23.2 and 1.22.1, NGINX Open Source Subscription before versions R2 P1 and R1 P1, and NGINX Plus before versions R27 P1 and R26 P1 have a vulnerability in the module… |
| CVE-2022-41741 | High (7.8) | 0.79% | — | Oct 19, 2022 | NGINX Open Source before versions 1.23.2 and 1.22.1, NGINX Open Source Subscription before versions R2 P1 and R1 P1, and NGINX Plus before versions R27 P1 and R26 P1 have a vulnerability in the module… |
| CVE-2021-3618 | High (7.4) | 2.0% | — | Mar 23, 2022 | ALPACA is an application layer protocol content confusion attack, exploiting TLS servers implementing different protocols but using compatible certificates, such as multi-domain or wildcard certificates. A MiTM attacker… |
| CVE-2017-20005 | Critical (9.8) | 3.3% | — | Jun 6, 2021 | NGINX before 1.13.6 has a buffer overflow for years that exceed four digits, as demonstrated by a file with a modification date in 1969 that causes an integer overflow (or a false modification date far in the future),… |
| CVE-2021-23017 | High (7.7) | 53% | — | Jun 1, 2021 | A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cause 1-byte memory overwrite, resulting in worker process crash or potential… |
| CVE-2019-20372 | Medium (5.3) | 15% | — | Jan 9, 2020 | NGINX before 1.17.7, with certain error_page configurations, allows HTTP request smuggling, as demonstrated by the ability of an attacker to read unauthorized web pages in environments where NGINX is being fronted by a… |
| CVE-2011-4968 | Medium (4.8) | 4.0% | — | Nov 19, 2019 | nginx http proxy module does not verify peer identity of https origin server which could facilitate man-in-the-middle attack (MITM) |
| CVE-2019-9516 | Medium (6.5) | 56% | — | Aug 13, 2019 | Some HTTP/2 implementations are vulnerable to a header leak, potentially leading to a denial of service. The attacker sends a stream of headers with a 0-length header name and 0-length header value, optionally Huffman… |
| CVE-2019-9513 | High (7.5) | 82% | — | Aug 13, 2019 | Some HTTP/2 implementations are vulnerable to resource loops, potentially leading to a denial of service. The attacker creates multiple request streams and continually shuffles the priority of the streams in a way that… |
| CVE-2019-9511 | High (7.5) | 60% | — | Aug 13, 2019 | Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of service. The attacker requests a large amount of data from a specified… |
| CVE-2018-16845 | Medium (6.1) | 9.8% | — | Nov 7, 2018 | nginx before versions 1.15.6, 1.14.1 has a vulnerability in the ngx_http_mp4_module, which might allow an attacker to cause infinite loop in a worker process, cause a worker process crash, or might result in worker… |
| CVE-2018-16844 | High (7.5) | 12% | — | Nov 7, 2018 | nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive CPU usage. This issue affects nginx compiled with the ngx_http_v2_module (not compiled by default)… |
| CVE-2018-16843 | High (7.5) | 47% | — | Nov 7, 2018 | nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive memory consumption. This issue affects nginx compiled with the ngx_http_v2_module (not compiled by… |
| CVE-2017-7529 | High (7.5) | 63% | — | Jul 13, 2017 | Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable to integer overflow vulnerability in nginx range filter module resulting into leak of potentially sensitive information triggered by specially crafted… |
| CVE-2016-1247 | High (7.8) | 4.9% | — | Nov 29, 2016 | The nginx package before 1.6.2-5+deb8u3 on Debian jessie, the nginx packages before 1.4.6-1ubuntu3.6 on Ubuntu 14.04 LTS, before 1.10.0-0ubuntu0.16.04.3 on Ubuntu 16.04 LTS, and before 1.10.1-0ubuntu1.1 on Ubuntu 16.10,… |
| CVE-2016-4450 | High (7.5) | 16% | — | Jun 7, 2016 | os/unix/ngx_files.c in nginx before 1.10.1 and 1.11.x before 1.11.1 allows remote attackers to cause a denial of service (NULL pointer dereference and worker process crash) via a crafted request, involving writing a… |
| CVE-2016-0747 | Medium (5.3) | 8.7% | — | Feb 15, 2016 | The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 does not properly limit CNAME resolution, which allows remote attackers to cause a denial of service (worker process resource consumption) via vectors related… |
| CVE-2016-0746 | Critical (9.8) | 8.9% | — | Feb 15, 2016 | Use-after-free vulnerability in the resolver in nginx 0.6.18 through 1.8.0 and 1.9.x before 1.9.10 allows remote attackers to cause a denial of service (worker process crash) or possibly have unspecified other impact… |
| CVE-2016-0742 | High (7.5) | 82% | — | Feb 15, 2016 | The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 allows remote attackers to cause a denial of service (invalid pointer dereference and worker process crash) via a crafted UDP DNS response. |
| CVE-2014-3556 | Medium (6.8) | 7.8% | — | Dec 29, 2014 | The STARTTLS implementation in mail/ngx_mail_smtp_handler.c in the SMTP proxy in nginx 1.5.x and 1.6.x before 1.6.1 and 1.7.x before 1.7.4 does not properly restrict I/O buffering, which allows man-in-the-middle… |
| CVE-2014-3616 | Medium (4.3) | 5.7% | — | Dec 8, 2014 | nginx 0.5.6 through 1.7.4, when using the same shared ssl_session_cache or ssl_session_ticket_key for multiple servers, can reuse a cached SSL session for an unrelated context, which allows remote attackers with certain… |
| CVE-2014-0088 | High (7.5) | 8.7% | — | Apr 29, 2014 | The SPDY implementation in the ngx_http_spdy_module module in nginx 1.5.10 before 1.5.11, when running on a 32-bit platform, allows remote attackers to execute arbitrary code via a crafted request. |
| CVE-2014-0133 | High (7.5) | 9.3% | — | Mar 28, 2014 | Heap-based buffer overflow in the SPDY implementation in nginx 1.3.15 before 1.4.7 and 1.5.x before 1.5.12 allows remote attackers to execute arbitrary code via a crafted request. |
| CVE-2013-4547 | High (7.5) | 68% | — | Nov 23, 2013 | nginx 0.8.41 through 1.4.3 and 1.5.x before 1.5.7 allows remote attackers to bypass intended restrictions via an unescaped space character in a URI. |
| CVE-2013-0337 | High (7.5) | 2.2% | — | Oct 27, 2013 | The default configuration of nginx, possibly 1.3.13 and earlier, uses world-readable permissions for the (1) access.log and (2) error.log files, which allows local users to obtain sensitive information by reading the… |
| CVE-2013-2070 | Medium (5.8) | 12% | — | Jul 20, 2013 | http/modules/ngx_http_proxy_module.c in nginx 1.1.4 through 1.2.8 and 1.3.0 through 1.4.0, when proxy_pass is used with untrusted HTTP servers, allows remote attackers to cause a denial of service (crash) and obtain… |
| CVE-2013-2028 | High (7.5) | 87% | — | Jul 20, 2013 | The ngx_http_parse_chunked function in http/ngx_http_parse.c in nginx 1.3.9 through 1.4.0 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a chunked Transfer-Encoding request… |
| CVE-2011-4963 | Medium (5) | 6.0% | — | Jul 26, 2012 | nginx/Windows 1.3.x before 1.3.1 and 1.2.x before 1.2.1 allows remote attackers to bypass intended access restrictions and access restricted files via (1) a trailing . (dot) or (2) certain "$index_allocation" sequences… |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.
Other products by F5
Big-ip Access Policy Manager · 630Big-ip Application Security Manager · 581Big-ip Advanced Firewall Manager · 552Big-ip Local Traffic Manager · 541Big-ip Policy Enforcement Manager · 533Big-ip Link Controller · 525Big-ip Application Acceleration Manager · 524Big-ip Analytics · 511Big-ip Global Traffic Manager · 490Big-ip Domain Name System · 469Big-ip Fraud Protection Service · 405Big-ip Webaccelerator · 297