PT-2026-60206 · F5+5 · Nginx Open Source+6
CVE-2026-60005
·
Published
2026-07-15
·
Updated
2026-08-31
CVSS v2.0
8.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
NGINX Plus (affected versions not specified)
NGINX Open Source (affected versions not specified)
Description
A flaw exists in the
ngx http slice module module. When the slice directive is used with unnamed regex captures or during a background cache update, unauthenticated remote attackers can send requests that trigger uninitialized memory access within the NGINX worker process. This can result in a limited disclosure of memory contents or cause the worker process to restart, leading to a denial of service. This is a data plane issue and does not expose the control plane. The ngx http slice module is not enabled by default and requires the --with-http slice module configuration parameter to be active.Recommendations
Upgrade to a vendor-listed fixed release.
As a temporary mitigation, disable the
ngx http slice module module by removing the --with-http slice module configuration parameter.Fix
DoS
Use of Uninitialized Resource
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linuxmint
Nginx Open Source
Nginx Plus
Nginx
Red Os
Rocky Linux
Ubuntu