CVE-2026-60005 Details
Description
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module. When the slice directive and unnamed regex captures are configured or when a background cache update happens, unauthenticated attackers can send requests that may cause uninitialized memory access in the NGINX worker process, leading to limited disclosure of memory or a restart. Impact: This vulnerability may allow remote, unauthenticated attackers to have limited control to disclose memory contents or restart the NGINX worker process. There is no control plane exposure; this is a data plane issue only. Note: The ngx_http_slice_module module is not enabled by default; it's enabled with the --with-http_slice_module configuration parameter. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
A vulnerability exists in the ngx_http_slice_module of NGINX Plus (versions 37.0.0.1 to 37.0.2.1) and NGINX Open Source (versions 1.31.2 and 1.30.0 to 1.30.3). When the slice directive is used with unnamed regex captures, or during a background cache update, unauthenticated attackers can send requests that lead to uninitialized memory access in the NGINX worker process. This could result in a limited disclosure of memory contents or cause the NGINX worker process to restart.
To address this vulnerability, users should upgrade to NGINX Plus version 37.0.3.1 or NGINX Open Source versions 1.31.3 or 1.30.4. For NGINX Instance Manager, versions 2.22.1 and later are recommended. Users of NGINX Gateway Fabric should upgrade to version 2.6.7. Additionally, to mitigate the vulnerability, it is advised not to use unnamed regex captures in configurations.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 15, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://my.f5.com/manage/s/article/K000162100 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-908 | Use of Uninitialized Resource | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| f5 nginx gateway fabric | >= 1.3.0, <= 1.6.2 >= 2.0.0, < 2.6.7 |
CPE
Remediation
| |
| f5 nginx ingress controller | >= 3.5.0, <= 3.7.2 >= 5.0.0, < 5.5.3 >= 2026-lts-r1, < 2026-lts-r4 4.0.0 4.0.1 |
CPE
Remediation
| |
| f5 nginx instance manager | >= 2.17.0, < 2.22.2 |
CPE
Remediation
| |
| f5 nginx open source | >= 1.30.0, < 1.30.4 1.31.2 |
CPE
Remediation
| |
| f5 nginx plus | >= 37.0.0.1, < 37.0.3.1 >= r33, < r36 r36 - r36 p1 r36 p2 r36 p3 r36 p4 r36 p5 r36 p6 |
CPE
Remediation
| |
| f5 waf | >= 4.11.0, <= 4.16.0 >= 5.2.0, <= 5.8.0 >= 5.9.0, < 5.13.4 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 11, 2026 | Reanalysis | [email protected] |
| Aug 6, 2026 | Initial Analysis | [email protected] |
| Jul 15, 2026 | New CVE Received | [email protected] |
| Jul 15, 2026 | CVE Modified | CISA-ADP |