Collected every two hours from specialised publications — each link leads to the original article.
nginx could be made to crash if it received specially crafted network traffic.
The container suse/nginx was updated. The following patches have been included in this update:
Three unpatched high-severity security flaws have been disclosed in theNGINX Ingress controllerfor Kubernetes that could be weaponized by a threat actor to ste…
The container suse/nginx was updated. The following patches have been included in this update:
The container suse/nginx was updated. The following patches have been included in this update:
The container suse/rmt-nginx was updated. The following patches have been included in this update:
It was discovered that parsing errors in the mp4 module of Nginx, a high-performance web and reverse proxy server, could result in denial of service, memory di…
It was discovered that parsing errors in the mp4 module of Nginx, a high-performance web and reverse proxy server, could result in denial of service, memory di…
A security issue was fixed in nginx's lua module.
The container suse/rmt-nginx was updated. The following patches have been included in this update:
nginx could be made to redirect network traffic.
Several security issues were fixed in nginx.
An update for the nginx:1.20 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact…
eCommerce servers are being targeted with remote access malware that hides on Nginx servers in a way that makes it virtually invisible to security solutions. '…
E-commerce platforms in the U.S., Germany, and France have come under attack from a new form of malware that targets Nginx servers in an attempt to masquerade …
E-commerce platforms in the U.S., Germany, and France have come under attack from a new form of malware that targets Nginx servers in an attempt to masquerade …
The package kubectl-ingress-nginx before version 1.0.4-1 is vulnerable to information disclosure.
A security issue was fixed in nginx.
Fixes CVE-2021-3618 nginx: ALPACA: Application Layer Protocol Confusion - Analyzing and Mitigating Cracks in TLS Authentication
Fixes CVE-2021-3618 nginx: ALPACA: Application Layer Protocol Confusion - Analyzing and Mitigating Cracks in TLS Authentication
A flaw was found in nginx. An off-by-one error while processing DNS responses allows a network attacker to write a dot character out of bounds in a heap alloca…
An update for the nginx:1.16 module is now available for Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 8.1 Extended Update Support, and Red Hat Enterpri…
Jamie Landeg-Jones and Manfred Paul discovered a buffer overflow vulnerability in NGINX, a small, powerful, scalable web/proxy server. NGINX has a buffer overf…
An update for rh-nginx116-nginx is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact o…