Known vulnerabilities in nginx-mod-devel
Vendor:
openEuler
Software:
nginx-mod-devel
Software CPE:
cpe:2.3:o:openeuler:nginx-mod-devel:*:*:*:*:*:openeuler:*:*
Website:
https://www.openeuler.org/
Total vulnerabilities:
21
Public exploits:
3
Known exploited (KEV):
2
Highest CVSSv4 Score:
9.2
Breakdown by Severity Chart
Vulnerabilities (21)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU137847 - Heap-based Buffer Overflow CVE-2026-42533 |
CWE-122 | High | 1.21.5-19 | 16.07.2026 |
SB2026071606 SB20260721112 SB20260721113 and 5 more |
||
| #VU137846 - Use of Uninitialized Resource CVE-2026-60005 |
CWE-908 | High | 1.21.5-19 | 16.07.2026 |
SB2026071606 SB20260721112 SB20260721113 and 3 more |
||
| #VU137845 - Use After Free CVE-2026-56434 |
CWE-416 | Medium | 1.21.5-19 | 16.07.2026 |
SB2026071606 SB20260721112 SB20260721113 and 3 more |
||
| #VU134864 - Out-of-bounds read CVE-2026-48142 |
CWE-125 | Medium | 1.21.5-15, 1.21.5-17, 1.24.0-13 | 18.06.2026 |
SB2026061844 SB2026061845 SB2026061846 and 9 more |
||
| #VU134861 - Heap-based Buffer Overflow CVE-2026-42055 |
CWE-122 | High | 1.21.5-15, 1.21.5-17, 1.24.0-13 | 18.06.2026 |
SB2026061844 SB2026061845 SB2026061846 and 11 more |
||
| #VU133362 - Resource exhaustion CVE-2026-49975 |
CWE-400 | High | 1.24.0-12 | 04.06.2026 |
SB2026060491 SB2026060492 SB2026060493 and 26 more |
||
| #VU132220 - Heap-based Buffer Overflow CVE-2026-9256 |
CWE-122 | Critical | 1.21.5-15 | 25.05.2026 |
SB2026052502 SB2026052504 SB2026052505 and 11 more |
||
| #VU131379 - Use After Free CVE-2026-40701 |
CWE-416 | Medium | 1.21.5-12, 1.21.5-14, 1.24.0-10 | 14.05.2026 |
SB2026051401 SB2026051497 SB2026051498 and 11 more |
||
| #VU131377 - Heap-based Buffer Overflow CVE-2026-42945 |
CWE-122 | Critical | 1.21.5-11, 1.21.5-13, 1.24.0-9, 1.24.0-10 | 14.05.2026 |
SB2026051401 SB2026051497 SB2026051498 and 25 more |
||
| #VU131375 - Uncontrolled Memory Allocation CVE-2026-42946 |
CWE-789 | Medium | 1.21.5-12, 1.21.5-14, 1.24.0-10 | 14.05.2026 |
SB2026051401 SB2026051497 SB2026051498 and 13 more |
||
| #VU131374 - Out-of-bounds read CVE-2026-42934 |
CWE-125 | Medium | 1.21.5-12, 1.21.5-14, 1.24.0-10 | 14.05.2026 |
SB2026051401 SB2026051497 SB2026051498 and 11 more |
||
| #VU124482 - Improper Neutralization of CRLF Sequences ('CRLF Injection') CVE-2026-28753 |
CWE-93 | Medium | 1.24.0-8 | 25.03.2026 |
SB2026032585 SB20260325200 SB2026041117 and 3 more |
||
| #VU124480 - Integer overflow CVE-2026-27784 |
CWE-190 | High | 1.24.0-8 | 25.03.2026 |
SB2026032585 SB20260325200 SB2026040801 and 16 more |
||
| #VU124478 - Heap-based Buffer Overflow CVE-2026-27654 |
CWE-122 | Medium | 1.24.0-8 | 25.03.2026 |
SB2026032585 SB20260325200 SB2026033174 and 16 more |
||
| #VU124475 - Out-of-bounds write CVE-2026-32647 |
CWE-787 | High | 1.24.0-8 | 25.03.2026 |
SB2026032585 SB20260325200 SB2026040801 and 16 more |
||
| #VU124473 - NULL Pointer Dereference CVE-2026-27651 |
CWE-476 | Medium | 1.24.0-8 | 25.03.2026 |
SB2026032585 SB20260325200 SB2026040801 and 16 more |
||
| #VU122335 - Acceptance of Extraneous Untrusted Data With Trusted Data CVE-2026-1642 |
CWE-349 | Medium | 1.21.5-9 | 05.02.2026 |
SB2026020501 SB2026020505 SB2026020511 and 21 more |
||
| #VU114082 - Out-of-bounds read CVE-2025-53859 |
CWE-125 | Low | 1.21.5-8, 1.21.5-10, 1.24.0-6 | 14.08.2025 |
SB2025081427 SB2025082564 SB2025082961 and 11 more |
||
| #VU103686 - Improper Authentication CVE-2025-23419 |
CWE-287 | Low | 1.24.0-3 | 06.02.2025 |
SB2025020653 SB2025020670 SB2025020671 and 16 more |
||
| #VU96020 - Out-of-bounds read CVE-2024-7347 |
CWE-125 | Medium | 1.21.5-5, 1.21.5-7, 1.24.0-2 | 14.08.2024 |
SB2024081481 SB2024081706 SB2024081707 and 25 more |
Showing elements 1 - 20 out of 21