VYPR

apk package

chainguard/commercial-nginx-plus

pkg:apk/chainguard/commercial-nginx-plus

Vulnerabilities (3)

  • CVE-2026-60005HigJul 15, 2026
    affected < 37.0.3.1-r0fixed 37.0.3.1-r0

    NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module. When the slice directive and unnamed regex captures are configured or when a background cache update happens, unauthenticated attackers can send requests that may cause uninitialized memory

  • CVE-2026-56434MedJul 15, 2026
    affected < 37.0.3.1-r0fixed 37.0.3.1-r0

    NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssi_module module. This vulnerability may exist when the Server-Side Includes (SSI), proxy_pass, and proxy_buffering off directives are configured. With this configuration, an unauthenticated attacker with man-

  • CVE-2026-42533HigJul 15, 2026
    affected < 37.0.3.1-r0fixed 37.0.3.1-r0

    A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the map's regex capture variables before referencing the map output variable. Alternatively, the same result could be achieved by using a non-cac