Executive brief
NGINX Plus and NGINX Open Source are widely used web server and proxy solutions. A vulnerability in the Server-Side Includes (SSI) module could allow an attacker with the ability to intercept network traffic to crash the NGINX worker process or cause limited memory corruption. This could lead to service interruptions or instability in the web server's operations.
Technical details
A heap buffer over-read vulnerability (CWE-416/Use After Free) exists in the ngx_http_ssi_module of NGINX. The issue is triggered when Server-Side Includes (SSI), proxy_pass, and proxy_buffering off directives are simultaneously configured. An unauthenticated attacker with man-in-the-middle (MITM) capabilities can control responses from an upstream server to trigger the flaw. Successful exploitation can lead to a restart of the NGINX worker process (DoS) or limited modification of memory. The vulnerability is restricted to the data plane and does not expose the control plane.
Affected products
- F5 NGINX Plus 37.0.0.1 to 37.0.3.1, R36 to R36 P7, R33 and later
- F5 NGINX Open Source 1.31.2 to 1.31.3, 0.8.11 to 1.30.4
Timeline
- 2026-07-15: advisory: Initial publication of the advisory by F5 and NVD.