
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-60005 is a use of uninitialized resource vulnerability (CWE-908) in the ngx_http_slice_module module of NGINX Plus and NGINX Open Source. When the slice directive and unnamed regex captures are configured, or when a background cache update occurs, unauthenticated remote attackers can send crafted requests that trigger uninitialized memory access in the NGINX worker process, leading to limited memory disclosure or a worker process restart. Affected versions include NGINX Open Source 1.15.8 through 1.30.3 and 1.31.2, and NGINX Plus R33 through R36 (before R36 P7) and 37.0.0.1 through 37.0.3.0. The vulnerability was published on July 15, 2026, with a CVSS v3.1 score of 8.2 (High) and a CVSS v4.0 score of 8.8 (High) (GitHub Advisory, F5 Advisory).
The root cause is CWE-908 (Use of Uninitialized Resource): the ngx_http_slice_module fails to properly initialize memory under two specific conditions — when the slice directive is used alongside unnamed regex captures in location matching, or during background cache update operations. In these scenarios, the NGINX worker process may access uninitialized memory regions, which an attacker can influence by sending specially crafted HTTP requests. No authentication or user interaction is required, and the attack is network-accessible with low complexity. The module is not compiled into NGINX by default and must be explicitly enabled with the --with-http_slice_module configuration parameter, which limits the attack surface to deployments that have opted into this feature (GitHub Advisory, F5 Advisory).
Successful exploitation can result in two primary outcomes: limited disclosure of NGINX worker process memory contents (confidentiality impact) and denial of service via worker process restart (high availability impact). There is no integrity impact and no control plane exposure — this is strictly a data plane issue. Memory disclosure is described as limited and not fully attacker-controlled, but could potentially expose sensitive data processed by the worker (e.g., request headers, cached content fragments). The worker process restart causes service disruption but does not result in persistent system compromise or lateral movement (GitHub Advisory, F5 Advisory).
There is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation as of the time of publication (GitHub Advisory). The vulnerability is automatable (no user interaction required) and exploitable by unauthenticated network attackers, but requires the non-default ngx_http_slice_module to be enabled. The EPSS score is approximately 0.61–0.71%, indicating a low near-term exploitation probability. No threat actor attribution has been reported, and the CVE is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.
ngx_http_slice_module enabled (compiled with --with-http_slice_module) and configured with the slice directive alongside unnamed regex captures in location blocks, or with background cache update (proxy_cache_background_update on) enabled.Range: bytes=... headers) from a single source IP against cached resources.error.log) showing worker process crashes or restarts (e.g., worker process XXXX exited on signal 11); access logs with repeated requests to the same sliced resource endpoint from external IPs./var/log/syslog, journalctl) or process monitoring; NGINX master process spawning replacement workers more frequently than normal.F5 has released patched versions: NGINX Open Source 1.30.4 and 1.31.3, and NGINX Plus R36 P7 and 37.0.3.1. Organizations should upgrade to these versions as the primary remediation (F5 Advisory, GitHub Advisory). As a workaround, if the ngx_http_slice_module is not required, recompile NGINX without the --with-http_slice_module parameter. Additionally, if the module is needed but the vulnerable configuration (unnamed regex captures with slice directive, or background cache updates) can be avoided, reconfiguring to eliminate those combinations will mitigate the risk. Network access controls limiting who can send requests to NGINX instances provide additional defense-in-depth.
The vulnerability was covered alongside two other NGINX flaws (CVE-2026-42533 and CVE-2026-56434) in a broader F5 patch release, with multiple security news outlets reporting on the combined advisory (CyberSecurityNews, GBHackers). Coverage emphasized that F5 patched multiple NGINX vulnerabilities simultaneously, with some outlets noting the potential for heap buffer overflow and code execution in the related CVEs. The Beazley Security Lab published an advisory covering all three NGINX CVEs together (Beazley Security). Community reaction on Mastodon and InfoSec.Exchange noted the patch release without significant alarm, consistent with the limited exploitation potential and non-default module requirement.
Fix availability across major Linux distributions and their releases.
bionic (esm-infra)
nginx
devel
nginx: 1.30.1-7ubuntu1
focal (esm-infra)
nginx
jammy
nginx: 1.18.0-6ubuntu14.17
noble
nginx: 1.24.0-2ubuntu7.14
resolute
nginx: 1.28.3-2ubuntu1.7
trusty (esm-infra-legacy)
nginx
xenial (esm-infra-legacy)
nginx
RHEL 8
:appstream:nginx:1.24:8100020260809162034:489197e6/nginx-0:1.24-8100020260809162034.489197e6.src
RHEL 9
:appstream:nginx-2:1.20.1-28.el9_8.5.src
RHEL 10
nginx-2:1.26.3-6.el10_2.6.src
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."