📦 Nginx Plus

by F5

🔍 What is Nginx Plus?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-24989

HIGH CVSS 7.5 Feb 14, 2024

This vulnerability allows attackers to cause denial of service by sending specially crafted requests to NGINX servers with HTTP/3 QUIC module enabled. It affects NGINX Plus and NGINX OSS when configur...

CVE-2023-44487

HIGH CVSS 7.5 Oct 10, 2023

CVE-2023-44487 is an HTTP/2 protocol vulnerability that allows attackers to cause denial of service by rapidly resetting streams, consuming server resources. This affects any system using HTTP/2, incl...

CVE-2026-1642

MEDIUM CVSS 5.9 Feb 4, 2026

A vulnerability in NGINX OSS and NGINX Plus allows attackers in a man-in-the-middle position on the upstream server side to inject plain text data into responses from proxied TLS servers. This affects...

CVE-2025-23419

MEDIUM CVSS 4.3 Feb 5, 2025

This CVE describes a client certificate authentication bypass vulnerability in nginx when multiple server blocks share the same IP/port. Attackers can exploit TLS session resumption to bypass client c...

CVE-2024-7347

MEDIUM CVSS 4.7 Aug 14, 2024

This vulnerability in NGINX's ngx_http_mp4_module allows attackers to cause memory over-read and worker process termination by uploading specially crafted MP4 files. Only NGINX installations built wit...

CVE-2024-32760

MEDIUM CVSS 6.5 May 29, 2024

This vulnerability in NGINX Plus and NGINX OSS allows attackers to cause denial of service by sending specially crafted HTTP/3 requests when the QUIC module is enabled. The worker processes may termin...

CVE-2024-35200

MEDIUM CVSS 5.3 May 29, 2024

This vulnerability allows attackers to cause denial of service by sending specially crafted HTTP/3 requests to NGINX servers configured with the QUIC module. When exploited, NGINX worker processes ter...