Impact
Nginx versions that enable the slice module can be tricked into accessing uninitialized memory during request processing or while performing a background cache update. This behaviour allows an unauthenticated attacker to send crafted HTTP requests that cause the worker process to leak portions of memory or to crash and restart. The vulnerability does not expose the control plane; it is confined to the data plane where HTTP requests are handled.
Affected Systems
The flaw affects F5:NGINX Open Source and F5:NGINX Plus distributions that are compiled with the http_slice_module enabled using the --with-http_slice_module flag. A background cache update must also be enabled for the advisory to apply to any build. No specific version information is available for affected builds.
Risk and Exploitability
The vulnerability is scored high with a CVSS of 8.8, indicating a severe impact. The EPSS score of less than 1% suggests that exploit activity is rare, and the flaw is not currently catalogued in CISA’s KEV list. The likely attack vector is sending HTTP requests that trigger the slice logic. Attackers would reach the vulnerability over standard network traffic, sending HTTP requests that trigger the slice logic. Successful exploitation can lead to limited data disclosure or a restart of the Nginx worker process, but requires no privileged access or additional systems integrated with the control plane.
OpenCVE Enrichment
Ubuntu USN