« Volver al listado

CVE-2026-27654

Estado: ModificadaAlta (8.8)—

NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_dav_module module that might allow an attacker to trigger a buffer overflow to the NGINX worker process; this vulnerability may result in termination of the NGINX worker process or modification of source or destination file names outside the document root. This issue affects NGINX Open Source and NGINX Plus when the configuration file uses DAV module MOVE or COPY methods, prefix location (nonregular expression location configuration), and alias directives. The integrity impact is constrained because the NGINX worker process user has low privileges and does not have access to the entire system. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vector N/A:H sin autenticación indica exposición remota en servicio web (NGINX DAV). Buffer overflow (CWE-122/120) puede modificar archivos o crashear el proceso (DoS/integridad).

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-27654",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-27654",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-03-24T15:14:50.235649Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "f5sirt@f5.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.2,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 4.2,
        "exploitabilityScore": 3.9
      },
      {
        "type": "Secondary",
        "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.2,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 4.2,
        "exploitabilityScore": 3.9
      }
    ],
    "cvssMetricV40": [
      {
        "type": "Secondary",
        "source": "f5sirt@f5.com",
        "cvssData": {
          "Safety": "NOT_DEFINED",
          "version": "4.0",
          "Recovery": "NOT_DEFINED",
          "baseScore": 8.8,
          "Automatable": "NOT_DEFINED",
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "valueDensity": "NOT_DEFINED",
          "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
          "exploitMaturity": "NOT_DEFINED",
          "providerUrgency": "NOT_DEFINED",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "attackRequirements": "NONE",
          "privilegesRequired": "NONE",
          "subIntegrityImpact": "NONE",
          "vulnIntegrityImpact": "LOW",
          "integrityRequirement": "NOT_DEFINED",
          "modifiedAttackVector": "NOT_DEFINED",
          "subAvailabilityImpact": "NONE",
          "vulnAvailabilityImpact": "HIGH",
          "availabilityRequirement": "NOT_DEFINED",
          "modifiedUserInteraction": "NOT_DEFINED",
          "modifiedAttackComplexity": "NOT_DEFINED",
          "subConfidentialityImpact": "NONE",
          "vulnConfidentialityImpact": "NONE",
          "confidentialityRequirement": "NOT_DEFINED",
          "modifiedAttackRequirements": "NOT_DEFINED",
          "modifiedPrivilegesRequired": "NOT_DEFINED",
          "modifiedSubIntegrityImpact": "NOT_DEFINED",
          "modifiedVulnIntegrityImpact": "NOT_DEFINED",
          "vulnerabilityResponseEffort": "NOT_DEFINED",
          "modifiedSubAvailabilityImpact": "NOT_DEFINED",
          "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
          "modifiedSubConfidentialityImpact": "NOT_DEFINED",
          "modifiedVulnConfidentialityImpact": "NOT_DEFINED"
        }
      }
    ]
  },
  "affected": [
    {
      "source": "f5sirt@f5.com",
      "affectedData": [
        {
          "vendor": "F5",
          "modules": [
            "ngx_http_dav_module"
          ],
          "product": "NGINX Open Source",
          "versions": [
            {
              "status": "affected",
              "version": "1.29.0",
              "lessThan": "1.29.7",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "0.5.13",
              "lessThan": "1.28.3",
              "versionType": "semver"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "vendor": "F5",
          "modules": [
            "ngx_http_dav_module"
          ],
          "product": "NGINX Plus",
          "versions": [
            {
              "status": "affected",
              "version": "R36",
              "lessThan": "R36 P3",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "R35",
              "lessThan": "R35 P2",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "R34",
              "lessThan": "*",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "R33",
              "lessThan": "*",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "R32",
              "lessThan": "R32 P5",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    },
    {
      "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
      "affectedData": [
        {
          "cpes": [
            "cpe:/o:redhat:enterprise_linux:10.1"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat Enterprise Linux 10",
          "versions": [
            {
              "status": "unaffected",
              "version": "2:1.26.3-2.el10_1.1",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "nginx",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/o:redhat:enterprise_linux_eus:10.0"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat Enterprise Linux 10.0 Extended Update Support",
          "versions": [
            {
              "status": "unaffected",
              "version": "2:1.26.3-1.el10_0.8",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "nginx",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:enterprise_linux:8"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat Enterprise Linux 8",
          "versions": [
            {
              "status": "unaffected",
              "version": "8100020260401080144.489197e6",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "nginx:1.24",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:enterprise_linux:9"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat Enterprise Linux 9",
          "versions": [
            {
              "status": "unaffected",
              "version": "9070020260331134728.9",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "nginx:1.24",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:enterprise_linux:9"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat Enterprise Linux 9",
          "versions": [
            {
              "status": "unaffected",
              "version": "2:1.20.1-24.el9_7.2",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "nginx",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:enterprise_linux:9"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat Enterprise Linux 9",
          "versions": [
            {
              "status": "unaffected",
              "version": "9070020260407080353.9",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "nginx:1.26",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:rhel_e4s:9.0"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
          "versions": [
            {
              "status": "unaffected",
              "version": "1:1.20.1-10.el9_0.3",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "nginx",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:rhel_e4s:9.2"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
          "versions": [
            {
              "status": "unaffected",
              "version": "1:1.20.1-14.el9_2.5",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "nginx",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:rhel_eus:9.4"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat Enterprise Linux 9.4 Extended Update Support",
          "versions": [
            {
              "status": "unaffected",
              "version": "1:1.20.1-16.el9_4.5",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "nginx",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:rhel_eus:9.4"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat Enterprise Linux 9.4 Extended Update Support",
          "versions": [
            {
              "status": "unaffected",
              "version": "9040020260504195322.9",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "nginx:1.24",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:rhel_eus:9.6"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat Enterprise Linux 9.6 Extended Update Support",
          "versions": [
            {
              "status": "unaffected",
              "version": "2:1.20.1-22.el9_6.5",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "nginx",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:rhel_eus:9.6"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat Enterprise Linux 9.6 Extended Update Support",
          "versions": [
            {
              "status": "unaffected",
              "version": "9060020260504194843.9",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "nginx:1.24",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:rhel_eus:9.6"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat Enterprise Linux 9.6 Extended Update Support",
          "versions": [
            {
              "status": "unaffected",
              "version": "9060020260504154614.9",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "nginx:1.26",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:hummingbird:1"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat Hardened Images",
          "versions": [
            {
              "status": "unaffected",
              "version": "1.30.0-1.hum1",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "nginx-main",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:rhui:5::el9"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat Update Infrastructure 5",
          "versions": [
            {
              "status": "unaffected",
              "version": "1776868774",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "rhui5/cds-rhel9",
          "collectionURL": "https://catalog.redhat.com/software/containers/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:rhui:5::el9"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat Update Infrastructure 5",
          "versions": [
            {
              "status": "unaffected",
              "version": "1776868842",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "rhui5/rhua-rhel9",
          "collectionURL": "https://catalog.redhat.com/software/containers/",
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-03-24T15:16:33.130",
  "references": [
    {
      "url": "https://my.f5.com/manage/s/article/K000160382",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "f5sirt@f5.com"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:10065",
      "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:13634",
      "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:13680",
      "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:13839",
      "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:14836",
      "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:15942",
      "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:15943",
      "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:15945",
      "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:15966",
      "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:6906",
      "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:6907",
      "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:6923",
      "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:7002",
      "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:7343",
      "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:8346",
      "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
    },
    {
      "url": "https://access.redhat.com/security/cve/CVE-2026-27654",
      "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
    },
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2450776",
      "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
    },
    {
      "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27654.json",
      "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "f5sirt@f5.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-122"
        }
      ]
    },
    {
      "type": "Secondary",
      "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
      "description": [
        {
          "lang": "en",
          "value": "CWE-120"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_dav_module module that might allow an attacker to trigger a buffer overflow to the NGINX worker process; this vulnerability may result in termination of the NGINX worker process or modification of source or destination file names outside the document root. This issue affects NGINX Open Source and NGINX Plus when the configuration file uses DAV module MOVE or COPY methods, prefix location (nonregular expression location configuration), and alias directives. The integrity impact is constrained because the NGINX worker process user has low privileges and does not have access to the entire system. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated."
    },
    {
      "lang": "es",
      "value": "NGINX Open Source y NGINX Plus tienen una vulnerabilidad en el módulo ngx_http_dav_module que podría permitir a un atacante desencadenar un desbordamiento de búfer en el proceso de trabajador de NGINX; esta vulnerabilidad puede resultar en la terminación del proceso de trabajador de NGINX o la modificación de nombres de archivos de origen o destino fuera del directorio raíz de documentos. Este problema afecta a NGINX Open Source y NGINX Plus cuando el archivo de configuración utiliza los métodos MOVE o COPY del módulo DAV, ubicación de prefijo (configuración de ubicación sin expresión regular) y directivas alias. El impacto en la integridad está restringido porque el usuario del proceso de trabajador de NGINX tiene privilegios bajos y no tiene acceso a todo el sistema. Nota: Las versiones de software que han alcanzado el Fin del Soporte Técnico (EoTS) no son evaluadas."
    }
  ],
  "lastModified": "2026-07-15T02:19:09.470",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:f5:nginx_plus:r32:p1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FA913184-EAAD-409E-99C6-AB979DAA93F3"
            },
            {
              "criteria": "cpe:2.3:a:f5:nginx_plus:r32:p2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "782DF180-1101-4D6A-A1D7-8DADBAF6D9D3"
            },
            {
              "criteria": "cpe:2.3:a:f5:nginx_plus:r32:p3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FB0B11F2-4748-492B-9906-F8C4C5EAFF12"
            },
            {
              "criteria": "cpe:2.3:a:f5:nginx_plus:r32:p4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "86B53968-1CCA-4CF3-8454-BB92EF64D10E"
            },
            {
              "criteria": "cpe:2.3:a:f5:nginx_plus:r33:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4F58BD02-EA76-4F32-87D6-430026C8553E"
            },
            {
              "criteria": "cpe:2.3:a:f5:nginx_plus:r33:p1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "46DC49B8-7286-4867-9CDA-1C1B469CD304"
            },
            {
              "criteria": "cpe:2.3:a:f5:nginx_plus:r33:p2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "43477C2E-7485-4146-B25C-F58D632CD85B"
            },
            {
              "criteria": "cpe:2.3:a:f5:nginx_plus:r33:p3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6A25B9CF-02C0-42DE-9C70-F2AD3ACE3CEB"
            },
            {
              "criteria": "cpe:2.3:a:f5:nginx_plus:r34:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "86358605-55F9-4F6F-846A-3F48738F6E05"
            },
            {
              "criteria": "cpe:2.3:a:f5:nginx_plus:r34:p1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7453D683-FCA7-46EE-BE49-5FD9A01D7F87"
            },
            {
              "criteria": "cpe:2.3:a:f5:nginx_plus:r34:p2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A977BF9F-D165-4B93-B4D2-A177883A5E75"
            },
            {
              "criteria": "cpe:2.3:a:f5:nginx_plus:r35:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C643CEF2-F421-4E2C-AD39-51CE820F2238"
            },
            {
              "criteria": "cpe:2.3:a:f5:nginx_plus:r35:p1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4958360C-7993-4C82-8685-202D4940CE01"
            },
            {
              "criteria": "cpe:2.3:a:f5:nginx_plus:r36:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "942CA349-3FF8-4B9D-B87E-FBA8930CE913"
            },
            {
              "criteria": "cpe:2.3:a:f5:nginx_plus:r36:p1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7993A0FB-BE7E-4634-BF7F-FDEE3582D3E7"
            },
            {
              "criteria": "cpe:2.3:a:f5:nginx_plus:r36:p2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "862EA47E-8D57-434E-9C8F-238325FB85B2"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:f5:nginx_open_source:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BABB440C-6106-42C6-8E67-101182F26C86",
              "versionEndIncluding": "0.9.7",
              "versionStartIncluding": "0.5.13"
            },
            {
              "criteria": "cpe:2.3:a:f5:nginx_open_source:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0E8049B1-4C36-4711-BB99-2721CF67FF81",
              "versionEndExcluding": "1.28.3",
              "versionStartIncluding": "1.0.0"
            },
            {
              "criteria": "cpe:2.3:a:f5:nginx_open_source:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C0EFE28B-E8E5-464E-B407-96436CA87C8E",
              "versionEndExcluding": "1.29.7",
              "versionStartIncluding": "1.29.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "f5sirt@f5.com"
}