Exposure of Nginx

Reverse proxies, Web servers
221
exposure score
2,184,939
sites use
0
exploited
12
critical
Vexday analysis

O histórico de vulnerabilidades do Nginx reúne 132 CVEs catalogadas, com 11 classificadas como críticas e 29 surgidas apenas nos últimos 90 dias, indicando um ritmo recente de descobertas que merece acompanhamento contínuo. Embora nenhuma CVE esteja atualmente confirmada em exploração ativa no catálogo CISA KEV — taxa abaixo da média geral do catálogo —, o score EPSS mais alto observado atinge 0,99098, sugerindo que ao menos uma vulnerabilidade tem probabilidade muito elevada de exploração. A CVE mais perigosa em evidência hoje é CVE-2025-1974, com EPSS de 0,991, o que a coloca em patamar de risco imediato e exige priorização nas rotinas de patch. O tipo de falha mais recorrente é CWE-20 (validação inadequada de entrada), padrão que tende a manifestar-se em superfícies de ataque amplas, especialmente em componentes voltados ao processamento de requisições externas.

CVEs

139 results
CVE-2025-1974CRITICALingress-nginx admission controller RCE escalationEPSS 99.5%CVE-2025-1098HIGHingress-nginx controller - configuration injection via unsanitized mirror annotationsEPSS 83.4%CVE-2026-42945CRITICALNGINX ngx_http_rewrite_module vulnerabilityEPSS 66.0%CVE-2017-7529Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable to integer overflow vulnerability in nginx range filter module resultinEPSS 62.6%CVE-2023-5044HIGHCode injection via nginx.ingress.kubernetes.io/permanent-redirect annotationEPSS 56.6%CVE-2021-23017A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cauEPSS 53.5%CVE-2018-16843MEDIUMnginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive memory consumption.EPSS 47.1%CVE-2026-33032CRITICALNginx UI: Unauthenticated MCP Endpoint Allows Remote Nginx TakeoverEPSS 38.5%CVE-2025-1097HIGHingress-nginx controller - configuration injection via unsanitized auth-tls-match-cn annotationEPSS 35.4%CVE-2025-24514HIGHingress-nginx controller - configuration injection via unsanitized auth-url annotationEPSS 32.5%CVE-2024-49368HIGHUnchecked logrotate settings lead to arbitrary command executionEPSS 27.5%CVE-2024-7646HIGHA security issue was discovered in ingress-nginx where an actor with permission to create Ingress objects (in the `networking.k8s.io` or `exEPSS 27.0%CVE-2026-27944CRITICALNginx UI: Unauthenticated Backup Download with Encryption Key DisclosureEPSS 22.2%CVE-2026-27654HIGHNGINX ngx_http_dav_module vulnerabilityEPSS 21.7%CVE-2018-16844MEDIUMnginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive CPU usage. This issEPSS 12.4%CVE-2026-9256CRITICALNGINX ngx_http_rewrite_module vulnerabilityEPSS 10.1%CVE-2018-16845HIGHnginx before versions 1.15.6, 1.14.1 has a vulnerability in the ngx_http_mp4_module, which might allow an attacker to cause infinite loop inEPSS 9.8%CVE-2026-3288HIGHingress-nginx rewrite-target nginx configuration injectionEPSS 6.3%CVE-2024-22198HIGHAuthenticated (user role) arbitrary command execution by modifying `start_cmd` setting (GHSL-2023-268)EPSS 4.1%CVE-2026-42055CRITICALNGINX ngx_http_proxy_v2_module and ngx_http_grpc_module vulnerabilityEPSS 4.0%