Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2013-2028

84
FAUCET Score

CVE-2013-2028 describes a critical vulnerability in nginx versions 1.3.9 through 1.4.0, specifically within the ngx_http_parse_chunked function. This flaw allows remote attackers to trigger a stack-based buffer overflow and integer signedness error by sending a crafted chunked Transfer-Encoding request with a large chunk size, affecting products like F5 Nginx and Fedora Nginx. The vulnerability is highly severe, with a CVSS score of 7.5, indicating it can be exploited remotely without authentication and with low attack complexity. Successful exploitation can lead to a denial of service (crash) and potentially arbitrary code execution, posing a significant risk to affected systems. This CVE has known public exploits, including Metasploit modules and several entries on ExploitDB demonstrating denial of service and remote overflow capabilities. It has garnered significant community attention, with multiple discussions and media coverage, indicating its widespread recognition and potential for active exploitation.

Impacted Technologies

VendorProductVersion(s)CPE
>= 1.3.9, <= 1.4.0CPE matchmatch criteria
cpe:2.3:a:f5:nginx:*:*:*:*:*:*:*:*
19CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:19:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

7.5HIGH

AV:N/AC:L/Au:N/C:P/I:P/A:P

Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
Access Vector
NETWORK
Access Complexity
LOW
Authentication
NONE
Exploitability Score
10.0
Impact Score
6.4
CvssVersion
2.0

Exploit Intelligence

EPSS Score
87.48%
Probability of exploitation in next 30 days
EPSS Percentile
99.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
Metasploit: Nginx HTTP Server 1.3.9-1.4.0 Chunked Encoding Stack Buffer Overflow · May 7, 2013
ExploitDB: EDB-32277 · Mar 15, 2014
This CVE's current EPSS score of 0.8748 is in the 100th percentile among its peer group of 51,485 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (9)

dahuapatch availablevia llm_extracted
Fixed in: 1.4.1+
View patch
dfinitypatch availablevia llm_extracted
Fixed in: 1.5.0
View patch
github_advisorypatch availablevia nvd_reference
View patch
jfrogpatch availablevia llm_extracted
Fixed in: 1.5.0
View patch
liferaypatch availablevia llm_extracted
Fixed in: 1.4.1
View patch
netgearpatch availablevia llm_extracted
Fixed in: 1.5.0+, 1.4.1+
View patch
opensshpatch availablevia llm_extracted
Fixed in: 1.5.0
View patch
power_bipatch availablevia llm_extracted
Fixed in: 1.4.1
View patch
terraformpatch availablevia llm_extracted
Fixed in: 1.5.0
View patch

Vendor Advisories (8)

liferayllm-liferay-274279b0c3fc755eCRITICAL

Stack-based buffer overflow with specially crafted request

Jan 1, 2013
jfrogllm-jfrog-b767a10a232a5085CRITICAL

Stack-based buffer overflow with specially crafted request

Jan 1, 2013
opensshllm-openssh-12469d767333f5baHIGH

Stack-based buffer overflow with specially crafted request

Jan 1, 2013
power_billm-power_bi-e7589a2322ff84f6CRITICAL

Stack-based buffer overflow with specially crafted request

Jan 1, 2013
dfinityllm-dfinity-6d2e512d066f9259CRITICAL

Stack-based buffer overflow with specially crafted request

Jan 1, 2013
dahuallm-dahua-e41c903d3f82a123HIGH

Stack-based buffer overflow with specially crafted request

terraformllm-terraform-d0dff4f076f832aaCRITICAL

Stack-based buffer overflow with specially crafted request

netgearllm-netgear-18d2fce1ddbb53bdHIGH

Stack-based buffer overflow with specially crafted request

References

lists.fedoraproject.org / pipermail/package-announce/2013-May/105176.html
Third Party Advisory
mailman.nginx.org / pipermail/nginx-announce/2013/000112.html
MitigationPatchVendor Advisory
nginx.org / download/patch.2013.chunked.txt
PatchVendor Advisory
packetstormsecurity.com / files/121675/Nginx-1.3.9-1.4.0-Denial-Of-Service.html
ExploitThird Party AdvisoryVDB Entry
secunia.com / advisories/55181
Third Party Advisory
security.gentoo.org / glsa/glsa-201310-04.xml
Third Party Advisory
github.com / rapid7/metasploit-framework/pull/1834
PatchThird Party Advisory
osvdb.org / 93037
Broken Link
securityfocus.com / bid/59699
Third Party AdvisoryVDB Entry
vnsecurity.net / 2013/05/analysis-of-nginx-cve-2013-2028
Broken Link