PT-2026-60206 · F5+5 · Nginx Open Source+6

CVE-2026-60005

·

Published

2026-07-15

·

Updated

2026-08-31

CVSS v2.0

8.5

High

VectorAV:N/AC:L/Au:N/C:P/I:N/A:C
Name of the Vulnerable Software and Affected Versions NGINX Plus (affected versions not specified) NGINX Open Source (affected versions not specified)
Description A flaw exists in the ngx http slice module module. When the slice directive is used with unnamed regex captures or during a background cache update, unauthenticated remote attackers can send requests that trigger uninitialized memory access within the NGINX worker process. This can result in a limited disclosure of memory contents or cause the worker process to restart, leading to a denial of service. This is a data plane issue and does not expose the control plane. The ngx http slice module is not enabled by default and requires the --with-http slice module configuration parameter to be active.
Recommendations Upgrade to a vendor-listed fixed release. As a temporary mitigation, disable the ngx http slice module module by removing the --with-http slice module configuration parameter.

Fix

DoS

Use of Uninitialized Resource

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:59216
ALSA-2026:59220
ALSA-2026:59362
ALSA-2026:59490
ALSA-2026:59496
BDU:2026-10487
BIT-NGINX-2026-60005
BIT-NGINX-GATEWAY-2026-60005
CVE-2026-60005
ECHO-0DAB-2681-8319
OESA-2026-3216
OPENSUSE-SU-2026:11295-1
RHSA-2026:46012
USN-8563-1

Affected Products

Linuxmint
Nginx Open Source
Nginx Plus
Nginx
Red Os
Rocky Linux
Ubuntu