Impact:
This vulnerability may allow remote, unauthenticated attackers to have limited control to disclose memory contents or restart the NGINX worker process. There is no control plane exposure; this is a data plane issue only.
Note: The ngx_http_slice_module module is not enabled by default; it's enabled with the --with-http_slice_module configuration parameter.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
Ubuntu USN |
USN-8563-1 | nginx vulnerabilities |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 11 Aug 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:f5:nginx_ingress_controller:*:*:*:*:*:*:*:* cpe:2.3:a:f5:nginx_ingress_controller:4.0.0:*:*:*:*:*:*:* cpe:2.3:a:f5:nginx_ingress_controller:4.0.1:*:*:*:*:*:*:* cpe:2.3:a:f5:nginx_plus:*:*:*:*:*:*:*:* cpe:2.3:a:f5:nginx_plus:37.0.0:*:*:*:*:*:*:* cpe:2.3:a:f5:nginx_plus:r36:-:*:*:*:*:*:* cpe:2.3:a:f5:nginx_plus:r36:p1:*:*:*:*:*:* cpe:2.3:a:f5:nginx_plus:r36:p2:*:*:*:*:*:* cpe:2.3:a:f5:nginx_plus:r36:p3:*:*:*:*:*:* cpe:2.3:a:f5:nginx_plus:r36:p4:*:*:*:*:*:* cpe:2.3:a:f5:nginx_plus:r36:p5:*:*:*:*:*:* cpe:2.3:a:f5:nginx_plus:r36:p6:*:*:*:*:*:* |
cpe:2.3:a:f5:nginx_ingress_controller:*:*:*:*:continuous_releases:*:*:* cpe:2.3:a:f5:nginx_ingress_controller:*:*:*:*:long-term_support:*:*:* cpe:2.3:a:f5:nginx_ingress_controller:4.0.0:*:*:*:continuous_releases:*:*:* cpe:2.3:a:f5:nginx_ingress_controller:4.0.1:*:*:*:continuous_releases:*:*:* cpe:2.3:a:f5:nginx_plus:*:*:*:*:continuous_releases:*:*:* cpe:2.3:a:f5:nginx_plus:*:*:*:*:long-term_support:*:*:* cpe:2.3:a:f5:nginx_plus:r36:-:*:*:continuous_releases:*:*:* cpe:2.3:a:f5:nginx_plus:r36:p1:*:*:continuous_releases:*:*:* cpe:2.3:a:f5:nginx_plus:r36:p2:*:*:continuous_releases:*:*:* cpe:2.3:a:f5:nginx_plus:r36:p3:*:*:continuous_releases:*:*:* cpe:2.3:a:f5:nginx_plus:r36:p4:*:*:continuous_releases:*:*:* cpe:2.3:a:f5:nginx_plus:r36:p5:*:*:continuous_releases:*:*:* cpe:2.3:a:f5:nginx_plus:r36:p6:*:*:continuous_releases:*:*:* |
| Vendors & Products |
F5 nginx App Protect Waf
|
Wed, 29 Jul 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-824 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Wed, 15 Jul 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
F5
F5 nginx Open Source F5 nginx Plus |
|
| Vendors & Products |
F5
F5 nginx Open Source F5 nginx Plus |
Wed, 15 Jul 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 15 Jul 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module. When the slice directive and unnamed regex captures are configured or when a background cache update happens, unauthenticated attackers can send requests that may cause uninitialized memory access in the NGINX worker process, leading to limited disclosure of memory or a restart. Impact: This vulnerability may allow remote, unauthenticated attackers to have limited control to disclose memory contents or restart the NGINX worker process. There is no control plane exposure; this is a data plane issue only. Note: The ngx_http_slice_module module is not enabled by default; it's enabled with the --with-http_slice_module configuration parameter. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Title | NGINX ngx_http_slice_module vulnerability | |
| Weaknesses | CWE-908 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: f5
Published:
Updated: 2026-07-15T15:41:06.279Z
Reserved: 2026-07-08T15:49:43.059Z
Link: CVE-2026-60005
Updated: 2026-07-15T15:41:00.420Z
Status : Analyzed
Published: 2026-07-15T16:16:49.820
Modified: 2026-08-11T15:09:03.683
Link: CVE-2026-60005
OpenCVE Enrichment
Updated: 2026-08-04T07:15:03Z
Ubuntu USN