Exposure of Nginx

Reverse proxies, Web servers
221
exposure score
2,184,939
sites use
0
exploited
12
critical
Vexday analysis

O histórico de vulnerabilidades do Nginx reúne 132 CVEs catalogadas, com 11 classificadas como críticas e 29 surgidas apenas nos últimos 90 dias, indicando um ritmo recente de descobertas que merece acompanhamento contínuo. Embora nenhuma CVE esteja atualmente confirmada em exploração ativa no catálogo CISA KEV — taxa abaixo da média geral do catálogo —, o score EPSS mais alto observado atinge 0,99098, sugerindo que ao menos uma vulnerabilidade tem probabilidade muito elevada de exploração. A CVE mais perigosa em evidência hoje é CVE-2025-1974, com EPSS de 0,991, o que a coloca em patamar de risco imediato e exige priorização nas rotinas de patch. O tipo de falha mais recorrente é CWE-20 (validação inadequada de entrada), padrão que tende a manifestar-se em superfícies de ataque amplas, especialmente em componentes voltados ao processamento de requisições externas.

CVEs

139 results
CVE-2011-4968nginx http proxy module does not verify peer identity of https origin server which could facilitate man-in-the-middle attack (MITM)EPSS 4.0%CVE-2026-42530CRITICALNGINX Open-Source ngx_http_v3_module vulnerabilityEPSS 3.7%CVE-2026-42533CRITICALNGINX Map directive and Regex matching vulnerabilityEPSS 3.6%CVE-2025-24513MEDIUMingress-nginx controller - auth secret file path traversal vulnerabilityEPSS 3.5%CVE-2020-7621strong-nginx-controller through 1.0.2 is vulnerable to Command Injection. It allows execution of arbitrary command as part of the '_nginxCmdEPSS 2.9%CVE-2024-3739MEDIUMcym1102 nginxWebUI upload os command injectionEPSS 2.9%CVE-2025-23419MEDIUMTLS Session Resumption VulnerabilityEPSS 2.7%CVE-2023-5043HIGHIngress nginx annotation injection causes arbitrary command executionEPSS 2.2%CVE-2021-25742HIGHIngress-nginx custom snippets allows retrieval of ingress-nginx serviceaccount token and secrets across all namespacesEPSS 1.8%CVE-2020-27730In versions 3.0.0-3.9.0, 2.0.0-2.9.0, and 1.0.1, the NGINX Controller Agent does not use absolute paths when calling system utilities.EPSS 1.7%CVE-2021-21335MEDIUMBasic Authentication can be bypassed using a malformed usernameEPSS 1.7%CVE-2022-4886HIGHIngress-nginx `path` sanitization can be bypassed with `log_format` directiveEPSS 1.6%CVE-2024-22197HIGHAuthenticated (user role) remote command execution by modifying `nginx` settings (GHSL-2023-269)EPSS 1.5%CVE-2026-4342HIGHingress-nginx comment-based nginx configuration injectionEPSS 1.5%CVE-2020-5901In NGINX Controller 3.3.0-3.4.0, undisclosed API endpoints may allow for a reflected Cross Site Scripting (XSS) attack. If the victim user iEPSS 1.5%CVE-2021-25746HIGHIngress-nginx directive injection via annotationsEPSS 1.5%CVE-2021-25745HIGHIngress-nginx path can be pointed to service account token fileEPSS 1.2%CVE-2020-5910In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, the Neural Autonomic Transport System (NATS) messaging services in use by the NGINX ControlEPSS 1.2%CVE-2020-5863In NGINX Controller versions prior to 3.2.0, an unauthenticated attacker with network access to the Controller API can create unprivileged uEPSS 1.1%CVE-2022-41742HIGHNGINX ngx_http_mp4_module vulnerability CVE-2022-41742EPSS 1.1%