{"id":"ALPINE-CVE-2026-60005","details":"NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module. When the slice directive and unnamed regex captures are configured or when a background cache update happens, unauthenticated attackers can send requests that may cause uninitialized memory access in the NGINX worker process, leading to limited disclosure of memory or a restart.\n\nImpact:\nThis vulnerability may allow remote, unauthenticated attackers to have limited control to disclose memory contents or restart the NGINX worker process. There is no control plane exposure; this is a data plane issue only.\nNote: The ngx_http_slice_module module is not enabled by default; it's enabled with the --with-http_slice_module configuration parameter.\n\nNote: Software versions which have reached End of Technical Support (EoTS) are not evaluated.","modified":"2026-07-20T21:30:06.582700296Z","published":"2026-07-15T16:16:49.820Z","upstream":["CVE-2026-60005"],"references":[{"type":"ADVISORY","url":"https://security.alpinelinux.org/vuln/CVE-2026-60005"}],"affected":[{"package":{"name":"nginx","ecosystem":"Alpine:v3.21","purl":"pkg:apk/alpine/nginx?arch=source"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.26.3-r2"}]}],"ecosystem_specific":{},"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/alpine/ALPINE-CVE-2026-60005.json"}},{"package":{"name":"nginx","ecosystem":"Alpine:v3.22","purl":"pkg:apk/alpine/nginx?arch=source"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.28.3-r6"}]}],"ecosystem_specific":{},"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/alpine/ALPINE-CVE-2026-60005.json"}},{"package":{"name":"nginx","ecosystem":"Alpine:v3.23","purl":"pkg:apk/alpine/nginx?arch=source"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.28.3-r6"}]}],"ecosystem_specific":{},"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/alpine/ALPINE-CVE-2026-60005.json"}},{"package":{"name":"nginx","ecosystem":"Alpine:v3.24","purl":"pkg:apk/alpine/nginx?arch=source"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.30.4-r0"}]}],"ecosystem_specific":{},"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/alpine/ALPINE-CVE-2026-60005.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"}]}