A vulnerability exists in NGINX OSS and NGINX Plus when configured to proxy to upstream Transport Layer Security (TLS) servers. An attacker with a man-in-the-middle (MITM) position on the upstream server side—along with conditions beyond the attacker's control—may be able to inject plain text data into the response from an upstream proxied server. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CVSS Details
- CVSS 4.0 Base Score: 8.2 (HIGH)
- CVSS 4.0 Vector: (CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
- CVSS 3.1 Base Score: 5.9
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade nginx-mod-develUpgrade nginx-all-modulesUpgrade nginxUpgrade nginx-mod-http-xslt-filterUpgrade nginx-mod-mailUpgrade nginx-filesystemUpgrade nginx-mod-http-image-filterUpgrade nginx-mod-http-perlUpgrade nginx-mod-streamUpgrade nginx-core | Mar 9, 2026 | Mar 3, 2026 |
| Alpine Linux | — | Upgrade nginx | Feb 6, 2026 | Feb 4, 2026 |
| Amazon Linux Ami 2 | — | Upgrade nginx-mod-http-geoipUpgrade nginx-all-modulesUpgrade nginx-filesystemUpgrade nginxUpgrade nginx-mod-mailUpgrade nginx-coreUpgrade nginx-mod-streamUpgrade nginx-mod-develUpgrade nginx-mod-http-xslt-filterUpgrade nginx-mod-http-perlUpgrade nginx-debuginfoUpgrade nginx-mod-http-image-filter | May 20, 2026 | May 20, 2026 |
| Amazon_linux_2023 | — | Upgrade nginx-debugsourceUpgrade nginx-mod-http-perl-debuginfoUpgrade nginx-mod-http-image-filter-debuginfoUpgrade nginx-all-modulesUpgrade nginx-mod-http-xslt-filter-debuginfoUpgrade nginxUpgrade nginx-mod-develUpgrade nginx-mod-mailUpgrade nginx-mod-stream-debuginfoUpgrade nginx-mod-mail-debuginfoUpgrade nginx-core-debuginfoUpgrade nginx-mod-http-image-filterUpgrade nginx-mod-http-perlUpgrade nginx-filesystemUpgrade nginx-mod-http-xslt-filterUpgrade nginx-coreUpgrade nginx-mod-streamUpgrade nginx-debuginfo | Feb 20, 2026 | Feb 4, 2026 |
| Debian | — | Upgrade nginx | Feb 16, 2026 | Feb 16, 2026 |
| Gentoo Linux | — | Upgrade www-servers/nginx. | Aug 17, 2026 | Aug 17, 2026 |
| Nginx | — | Upgrade to nginx version 1.29.5Upgrade to nginx version 1.28.2 | Feb 5, 2026 | Feb 4, 2026 |
| Oracle_linux | — | Upgrade nginx-filesystemUpgrade nginx-mod-develUpgrade nginx-mod-streamUpgrade nginx-mod-http-xslt-filterUpgrade nginx-all-modulesUpgrade nginxUpgrade nginx-mod-mailUpgrade nginx-mod-http-image-filterUpgrade nginx-coreUpgrade nginx-mod-http-perl | Mar 5, 2026 | Feb 4, 2026 |
| Redhat_linux | — | Upgrade nginx-mod-http-perlUpgrade nginx-mod-http-xslt-filterUpgrade nginxUpgrade nginx-core-debuginfoUpgrade nginx-mod-http-xslt-filter-debuginfoUpgrade nginx-mod-http-image-filterUpgrade nginx-all-modulesUpgrade nginx-coreUpgrade nginx-mod-streamUpgrade nginx-debugsourceUpgrade nginx-mod-http-perl-debuginfoUpgrade nginx-mod-mailUpgrade nginx-filesystemUpgrade nginx-debuginfoUpgrade nginx-mod-mail-debuginfoUpgrade nginx-mod-stream-debuginfoUpgrade nginx-mod-http-image-filter-debuginfoUpgrade nginx-mod-devel | Mar 13, 2026 | Feb 4, 2026 |
| Rocky_linux | — | Upgrade nginx-mod-develUpgrade nginx-core-debuginfoUpgrade nginxUpgrade nginx-mod-http-image-filter-debuginfoUpgrade nginx-mod-http-xslt-filter-debuginfoUpgrade nginx-mod-stream-debuginfoUpgrade nginx-mod-streamUpgrade nginx-mod-http-xslt-filterUpgrade nginx-mod-http-perlUpgrade nginx-debuginfoUpgrade nginx-mod-http-image-filterUpgrade nginx-coreUpgrade nginx-debugsourceUpgrade nginx-mod-mail-debuginfoUpgrade nginx-mod-http-perl-debuginfoUpgrade nginx-mod-mail | Mar 9, 2026 | Mar 5, 2026 |
| Suse | — | Upgrade nginx-sourceUpgrade nginx | May 11, 2026 | Apr 10, 2026 |
| Ubuntu | — | Upgrade libnginx-mod-stream (Ubuntu Pro)Upgrade libnginx-mod-http-cache-purge (Ubuntu Pro)Upgrade nginxUpgrade libnginx-mod-http-xslt-filter (Ubuntu Pro)Upgrade nginx-fullUpgrade nginx-naxsi (Ubuntu Pro)Upgrade nginx-extrasUpgrade nginx (Ubuntu Pro)Upgrade nginx-full (Ubuntu Pro)Upgrade libnginx-mod-http-subs-filter (Ubuntu Pro)Upgrade nginx-light (Ubuntu Pro)Upgrade libnginx-mod-http-headers-more-filter (Ubuntu Pro)Upgrade libnginx-mod-http-geoip (Ubuntu Pro)Upgrade nginx-coreUpgrade libnginx-mod-http-auth-pam (Ubuntu Pro)Upgrade libnginx-mod-http-echo (Ubuntu Pro)Upgrade libnginx-mod-nchan (Ubuntu Pro)Upgrade libnginx-mod-http-image-filter (Ubuntu Pro)Upgrade libnginx-mod-http-ndk (Ubuntu Pro)Upgrade libnginx-mod-http-fancyindex (Ubuntu Pro)Upgrade libnginx-mod-http-lua (Ubuntu Pro)Upgrade nginx-extras (Ubuntu Pro)Upgrade libnginx-mod-mail (Ubuntu Pro)Upgrade libnginx-mod-http-uploadprogress (Ubuntu Pro)Upgrade libnginx-mod-http-upstream-fair (Ubuntu Pro)Upgrade libnginx-mod-http-dav-ext (Ubuntu Pro)Upgrade nginx-core (Ubuntu Pro)Upgrade nginx-common (Ubuntu Pro)Upgrade libnginx-mod-rtmp (Ubuntu Pro)Upgrade nginx-lightUpgrade libnginx-mod-http-perl (Ubuntu Pro) | Feb 13, 2026 | Feb 4, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | May 27, 2026 | Feb 4, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub