VYPR

Nginx Plus

by F5, Inc.

Source repositories

CVEs (23)

  • CVE-2024-7347MedAug 14, 2024
    risk 0.24cvss 4.7epss 0.00

    NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module, which might allow an attacker to over-read NGINX worker memory resulting in its termination, using a specially crafted mp4 file. The issue only affects NGINX if it is built with the…

  • CVE-2025-23419MedFeb 5, 2025
    risk 0.21cvss 4.3epss 0.03

    When multiple server blocks are configured to share the same IP address and port, an attacker can use session resumption to bypass client certificate authentication requirements on these servers. This vulnerability arises when TLS Session Tickets…

  • CVE-2025-53859LowAug 13, 2025
    risk 0.17cvss 3.7epss 0.00

    NGINX Open Source and NGINX Plus have a vulnerability in the ngx_mail_smtp_module that might allow an unauthenticated attacker to over-read NGINX SMTP authentication process memory; as a result, the server side may leak arbitrary bytes sent in a request to the authentication…

Page 2 of 2