NG

NGINX — Known Vulnerabilities

2 vulnerabilities mapped against this product across all versions. Grouped by the release each fix landed in — newest tracked release v2-clause.
Still affects the latest release (v2-clause) 2
CVE-2009-3896 Affects 0.6.1516–0.6.1516 CVSS 5.0 · Medium NVD ↗ Nov 24, 2009
src/http/ngx_http_parse.c in nginx (aka Engine X) 0.1.0 through 0.4.14, 0.5.x before 0.5.38, 0.6.x before 0.6.39, 0.7.x before 0.7.62, and 0.8.x before 0.8.14 allows remote attackers to cause a denial of service (NULL pointer dereference and worker process crash)…
CVE-2009-3898 Affects 0.6.1516–0.6.1516 CVSS 4.9 · Medium NVD ↗ Nov 24, 2009
Directory traversal vulnerability in src/http/modules/ngx_http_dav_module.c in nginx (aka Engine X) before 0.7.63, and 0.8.x before 0.8.17, allows remote authenticated users to create or overwrite arbitrary files via a .. (dot dot) in the Destination HTTP header for the…
Source: NVD · CISA KEV · data as of Jun 8, 2026