← Back to CVE List
Vulnerability Intelligence Report
NGINX ngx_http_slice_module vulnerability

CVE-2026-60005

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module. When the slice directive and unnamed regex captures are configured or when a background cache update happens, unauthenticated attackers can send requests that may cause uninitialized memory access in the NGINX worker process, leading to limited disclosure of memory or a restart. Impact: This vulnerability may allow remote, unauthenticated attackers to have limited control to disclose memory contents or restart the NGINX worker process. There is no control plane exposure; this is a data plane issue only. Note: The ngx_http_slice_module module is not enabled by default; it's enabled with the --with-http_slice_module configuration parameter. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

No Active Exploit Signals
CVSS Base Score
8.2
HIGH
Exploitability:3.9
Impact Score:4.3
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-908 ↗CWE-908 Use of Uninitialized Resource

Affected Products & Versions

Vendor Product Affected Versions
F5 NGINX Plus 37.0.0.1 < 37.0.3.1 (affected), R36 < R36 P7 (affected), R33 < * (affected)
F5 NGINX Open Source 1.31.2 < 1.31.3 (affected), 1.15.8 < 1.30.4 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityF5, Inc. · Vendor · USA
Reserved2026-07-08T15:49:43
Published2026-07-15T15:04:21
Patch Date2026-07-15
Last Updated2026-07-15T15:41:06

LINK COPIED TO CLIPBOARD