VYPR

rpm package

opensuse/nginx&distro=openSUSE Leap 16.0

pkg:rpm/opensuse/nginx&distro=openSUSE%20Leap%2016.0

Vulnerabilities (5)

  • CVE-2026-42533HigJul 15, 2026
    affected < 1.27.2-160000.7.1fixed 1.27.2-160000.7.1

    A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the map's regex capture variables before referencing the map output variable. Alternatively, the same result could be achieved by using a non-cac

  • CVE-2026-48142MedJun 17, 2026
    affected < 1.27.2-160000.6.1fixed 1.27.2-160000.6.1

    NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When content is served or proxied through a location block with both source_charset utf-8; and a charset directive (for example, charset koi8-r;) configured, remote, unauthenticated attac

  • CVE-2026-42055HigJun 17, 2026
    affected < 1.27.2-160000.6.1fixed 1.27.2-160000.6.1

    NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass directives are used to proxy HTTP/2 traffic, the ignore_invalid_headers directive is set

  • CVE-2026-9256HigMay 22, 2026
    affected < 1.27.2-160000.5.1fixed 1.27.2-160000.5.1

    NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite directive uses a regex pattern with distinct, overlapping Perl-Compatible Regular Expression (PCRE) captures (for example, ^/((.*))$) and a replac

  • CVE-2026-40460MedMay 13, 2026
    affected < 1.27.2-160000.6.1fixed 1.27.2-160000.6.1

    When NGINX Plus or NGINX Open Source are configured to use the HTTP/3 QUIC module, an attacker may be able to spoof their source IP address allowing for bypass of authorization or bypass of rate limiting.  Note: Software versions which have reached End of Technical Support (EoTS)