CVE-2026-60005

Published Jul 15, 2026

Last updated 14 days ago

CVSS high 8.8
web application

Overview

Description
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module. When the slice directive and unnamed regex captures are configured or when a background cache update happens, unauthenticated attackers can send requests that may cause uninitialized memory access in the NGINX worker process, leading to limited disclosure of memory or a restart. Impact: This vulnerability may allow remote, unauthenticated attackers to have limited control to disclose memory contents or restart the NGINX worker process. There is no control plane exposure; this is a data plane issue only. Note: The ngx_http_slice_module module is not enabled by default; it's enabled with the --with-http_slice_module configuration parameter. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Source
f5sirt@f5.com
NVD status
Analyzed
Products
nginx_gateway_fabric, nginx_ingress_controller, nginx_instance_manager, nginx_open_source, nginx_plus, waf

Risk scores

CVSS 4.0

Type
Secondary
Base score
8.8
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
HIGH

CVSS 3.1

Type
Primary
Base score
8.2
Impact score
4.2
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
Severity
HIGH

Weaknesses

f5sirt@f5.com
CWE-908

Social media

Hype score
Not currently trending
  1. 🚨 @nginxorg users, this is one to prioritize. A critical heap buffer overflow (CVE-2026-42533, CVSS 9.2) has been disclosed in both NGINX Open Source and NGINX Plus. The advisory also patches: • Memory disclosure (CVE-2026-60005) • Use-after-free (CVE-2026-56434) Most

    @jxngrx

    21 Jul 2026

    49 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    2 Replies

    0 Quotes

  2. nginx releases security updates (1.30.4 & 1.31.3): Fixes include: • CVE-2026-42533 – Buffer overflow • CVE-2026-60005 – Memory disclosure • CVE-2026-56434 – Use-after-free Update as soon as possible. #nginx #Vulnerability

    @ThreatByte

    17 Jul 2026

    4 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. 🚨 CVE-2026-42533, CVE-2026-60005 & CVE-2026-56434: F5 has disclosed three high-severity vulnerabilities affecting NGINX Plus and NGINX Open Source, potentially leading to memory corruption, worker crashes, or remote code execution. #CyberSecurity #CVE #NGINX #F5 #ThreatWi

    @ThreatWire_

    16 Jul 2026

    52 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. 🔴 NGINX kullanıcılarının dikkatine! F5, NGINX ve NGINX Plus'ı etkileyen 3 yüksek önem dereceli güvenlik açığını duyurdu. • CVE-2026-42533 – Heap Buffer Overflow • CVE-2026-60005 – Uninitialized Memory Disclosure • CVE-2026-56434 – Use-After-Free Etk

    @ridvanyagli

    16 Jul 2026

    197 Impressions

    1 Retweet

    2 Likes

    2 Bookmarks

    0 Replies

    0 Quotes

  5. NGINX release-1.30.4 patches CVE-2026-42533 Critical security vulnerabilities (CVE-2026-42533, CVE-2026-60005, CVE-2026-56434) fixed. Upgrade carefully. → https://t.co/aKovKRAYKK

    @ReleasePort

    16 Jul 2026

    11 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. F5 patched the NGINX code execution flaw CVE-2026-42533, along with CVE-2026-60005 and CVE-2026-56434. Update NGINX Plus and Open Source builds now. #NGINX #CVE202642533 #CodeExecution #F5 #Vulnerability https://t.co/cds4Vr6BxO

    @Daily_CyberSec

    16 Jul 2026

    571 Impressions

    2 Retweets

    9 Likes

    3 Bookmarks

    0 Replies

    0 Quotes

Configurations

References

Sources include official advisories and independent security research.