apk package
chainguard/commercial-nginx-plus
pkg:apk/chainguard/commercial-nginx-plus
Vulnerabilities (3)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-60005 | Hig | 8.2 | < 37.0.3.1-r0 | 37.0.3.1-r0 | Jul 15, 2026 | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module. When the slice directive and unnamed regex captures are configured or when a background cache update happens, unauthenticated attackers can send requests that may cause uninitialized memory | |
| CVE-2026-56434 | Med | 6.5 | < 37.0.3.1-r0 | 37.0.3.1-r0 | Jul 15, 2026 | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssi_module module. This vulnerability may exist when the Server-Side Includes (SSI), proxy_pass, and proxy_buffering off directives are configured. With this configuration, an unauthenticated attacker with man- | |
| CVE-2026-42533 | Hig | 8.1 | < 37.0.3.1-r0 | 37.0.3.1-r0 | Jul 15, 2026 | A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the map's regex capture variables before referencing the map output variable. Alternatively, the same result could be achieved by using a non-cac |
- affected < 37.0.3.1-r0fixed 37.0.3.1-r0
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module. When the slice directive and unnamed regex captures are configured or when a background cache update happens, unauthenticated attackers can send requests that may cause uninitialized memory
- affected < 37.0.3.1-r0fixed 37.0.3.1-r0
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssi_module module. This vulnerability may exist when the Server-Side Includes (SSI), proxy_pass, and proxy_buffering off directives are configured. With this configuration, an unauthenticated attacker with man-
- affected < 37.0.3.1-r0fixed 37.0.3.1-r0
A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the map's regex capture variables before referencing the map output variable. Alternatively, the same result could be achieved by using a non-cac