PatchSiren cyber security CVE debrief
CVE-2026-60005 F5 CVE debrief
The ngx_http_slice_module module in NGINX Plus and NGINX Open Source is vulnerable to uninitialized memory access. This vulnerability allows unauthenticated attackers to send requests that may cause memory disclosure or NGINX worker process restarts when the slice directive and unnamed regex captures are configured or during background cache updates. The module is not enabled by default and requires the --with-http_slice_module configuration parameter. NGINX Plus and NGINX Open Source users should be aware of this vulnerability and take necessary actions to mitigate it. The vulnerability was published on 2026-07-15T16:16:49.820Z and has not been modified since then.
- Vendor
- F5
- Product
- NGINX Plus
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-15
- Original CVE updated
- 2026-08-06
- Advisory published
- 2026-07-15
- Advisory updated
- 2026-08-06
Who should care
NGINX Plus and NGINX Open Source users, administrators, and security teams should be aware of this vulnerability and take necessary actions to mitigate it. This includes reviewing and applying patches or updates, disabling the ngx_http_slice_module module if not required, and implementing compensating controls such as Web Application Firewalls (WAFs). Additionally, monitoring NGINX worker process logs for unusual restarts or memory access patterns and verifying the --with-http_slice_module configuration parameter is not enabled unless necessary is crucial. Affected operators, platforms, and security teams must prioritize patching or mitigating the vulnerability to prevent potential memory disclosure or worker process restarts. Vulnerability management and security teams should track exceptions, retest remediated assets, and close the item only after evidence is documented. NGINX Plus and NGINX Open Source deployments should be reviewed for exposure, with an assigned owner for follow-up. Compensating controls should be reviewed for exposed systems while remediation is scheduled and verified. Relevant monitoring, detection, and logs should be checked for exposed assets that need extra review. This vulnerability may allow remote, unauthenticated attackers to have limited control to disclose memory contents or restart the NGINX worker process. There is no control plane exposure; this is a data plane issue only. Software versions which have reached End of Technical Support (EoTS) are not evaluated. The ngx_http_slice_module module is not enabled by default; it's enabled with the --with-http_slice_module configuration parameter. The vulnerability exists in the ngx_http_slice_module module of NGINX Plus and NGINX Open Source. When the slice directive and unnamed regex captures are configured or when a background cache update happens, unauthenticated attackers can send requests that may cause uninitialized memory access in the NGINX worker process. This could lead to limited disclosure of memory or a restart of the NGINX worker process. Evidence and verification tasks should focus on defensive measures and limited source detail expansion with evidence-limit language. AI
Technical summary
The ngx_http_slice_module module in NGINX Plus and NGINX Open Source is vulnerable to uninitialized memory access. When the slice directive and unnamed regex captures are configured or during background cache updates, unauthenticated attackers can send requests that may cause memory disclosure or NGINX worker process restarts. The module is not enabled by default and requires the --with-http_slice_module configuration parameter. This vulnerability allows remote, unauthenticated attackers to have limited control to disclose memory contents or restart the NGINX worker process. There is no control plane exposure; this is a data plane issue only. Software versions which have reached End of Technical Support (EoTS) are not evaluated. NGINX Plus and NGINX Open Source users should prioritize patching or mitigating the vulnerability to prevent potential memory disclosure or worker process restarts.
Defensive priority
NGINX Plus and NGINX Open Source users should prioritize patching or mitigating the vulnerability in the ngx_http_slice_module module to prevent potential memory disclosure or worker process restarts.
Recommended defensive actions
- Review and apply patches or updates for NGINX Plus and NGINX Open Source to address the vulnerability in the ngx_http_slice_module module.
- Disable the ngx_http_slice_module module if not required.
- Implement compensating controls such as Web Application Firewalls (WAFs) to detect and prevent exploitation attempts.
- Monitor NGINX worker process logs for unusual restarts or memory access patterns.
- Verify that the --with-http_slice_module configuration parameter is not enabled unless necessary.
Evidence notes
The vulnerability exists in the ngx_http_slice_module module of NGINX Plus and NGINX Open Source. When the slice directive and unnamed regex captures are configured or when a background cache update happens, unauthenticated attackers can send requests that may cause uninitialized memory access in the NGINX worker process. This could lead to limited disclosure of memory or a restart of the NGINX worker process. The ngx_http_slice_module module is not enabled by default; it's enabled with the --with-http_slice_module configuration parameter. Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Official resources
-
CVE-2026-60005 CVE record
CVE.org
-
CVE-2026-60005 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-15T16:16:49.820Z and has not been modified since then.