HomeCVE Intelligence › CVE-2026-60005
CVSS 8.2 HIGH Security Vulnerability

CVE-2026-60005: NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module…

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module. When the slicedirective and unnamed regex captures are configured or when a background cache update happens, unauthenticated att…

8.2CVSS Score
HIGHSeverity
NOCISA KEV
0.6%EPSS Score
Security VulnerabilityImpact Type

📋 Vulnerability Details

CVE IDCVE-2026-60005
VendorUnknown Vendor
Affected ProductUnknown Product
Vulnerability TypeSecurity Vulnerability
CVSS Score8.2 (HIGH)
EPSS Score0.6% probability of exploitation in the next 30 days
Actively Exploited❌ No known exploitation
Patch StatusPending Vendor Disclosure
Reported ByCYBERDUDEBIVASH SENTINEL APEX Intelligence (via sentinel_apex)

🔬 Technical Analysis

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module. When the slicedirective and unnamed regex captures are configured or when a background cache update happens, unauthenticated attackers can send requests that may cause uninitialized memory access in the NGINX worker process, leading to limited disclosure of memory or a restart.

Impact: This vulnerability may allow remote, unauthenticated attackers to have limited control to disclose memory contents or restart the NGINX worker process. There is no control plane exposure; this is a data plane issue only. Note: The ngx_http_slice_modulemodule is not enabled by default; it's enabled with the --with-http_slice_moduleconfiguration parameter.

Note: Software versions which have reached End of Technical Sup

🎯 Known Indicators of Compromise

{"type":"indicator","value":"CVE-2026-60005","confidence_score":23.5,"first_seen":"2026-07-17","source_count":1}
⚡ DETECTION RULES AVAILABLE

Get CVE-2026-60005 Detection Pack

Sigma rules, YARA signatures, IOC table, and SIEM queries for Splunk, Elastic, Sentinel, and Chronicle — deployable in 5 minutes.

✓ Sigma Rules ✓ YARA Pack ✓ IOC Table ✓ SIEM Queries
🛡️ Get Detection Pack → 🔌 Access via API →

🔗 Related Intelligence