Impact
The flaw resides in the ngx_http_ssi_module of NGINX Plus and Open Source and is a CWE‑416 use‑after‑free vulnerability, also involving an out‑of‑bounds read (CWE‑125). When the SSI directive is enabled together with proxy_pass and proxy_buffering off, an attacker who can act as a man‑in‑the‑middle on the upstream link may trigger a use‑after‑free in the worker process. The resulting corrupt memory may be limited, and the worker can terminate, leading to a denial of service for the affected site.
Affected Systems
F5’s NGINX Open Source and NGINX Plus distributions are affected. The advisory does not list specific product versions; administrators should examine the latest release notes for each edition to find the fix, noting that versions that have reached end‑of‑technical support are not evaluated.
Risk and Exploitability
The CVSS score of 8.3 indicates high severity, while the EPSS score of less than 1 % suggests a low probability of exploitation at present. The issue is not listed in the CISA KEV catalog. The vulnerability can be abused only when an unauthenticated attacker can tamper with upstream responses, making the attack surface larger in deployments that do not authenticate or encrypt upstream traffic.
OpenCVE Enrichment
Ubuntu USN