Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2021-23017

65
FAUCET Score

CVE-2021-23017 is a high-severity vulnerability in the nginx resolver that allows a remote attacker to cause a 1-byte memory overwrite, potentially leading to a worker process crash or other impacts. This vulnerability affects products from f5, fedoraproject, netapp, openresty, and oracle. With a CVSS score of 7.7 (High), it has a network attack vector and high attack complexity, indicating a significant risk. While not on the KEV catalog, an exploit for Denial of Service is available on ExploitDB, and it has garnered notable community discussion and media coverage, suggesting active interest.

Impacted Technologies

VendorProductVersion(s)CPE
>= 0.6.18, < 1.20.1CPE matchmatch criteria
cpe:2.3:a:f5:nginx:*:*:*:*:*:*:*:*
< 1.19.3.2CPE matchmatch criteria
cpe:2.3:a:openresty:openresty:*:*:*:*:*:*:*:*
33CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*
34CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:a:netapp:ontap_select_deploy_administration_utility:-:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.7HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
LOW
Exploitability Score
2.2
Impact Score
5.5
CvssVersion
3.1

Exploit Intelligence

EPSS Score
53.46%
Probability of exploitation in next 30 days
EPSS Percentile
98.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
ExploitDB: EDB-50973 · Jul 11, 2022
This CVE's current EPSS score of 0.5346 is in the 98th percentile among its peer group of 8,918 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (40)

dahuapatch availablevia llm_extracted
Fixed in: 1.20.1+
View patch
dfinitypatch availablevia llm_extracted
Fixed in: 1.21.0
View patch
jfrogpatch availablevia llm_extracted
Fixed in: 1.21.0
View patch
liferaypatch availablevia llm_extracted
Fixed in: 1.20.1
View patch
microsoftpatch availablevia msrc
Product: cm1 nginx 1.20.1-1 on CBL Mariner 1.0Fixed in: 1.20.1-1
microsoftpatch availablevia msrc
Product: 17079-16820Fixed in: 1.20.1-1
netgearpatch availablevia llm_extracted
Fixed in: 1.21.0+, 1.20.1+
View patch
opensshpatch availablevia llm_extracted
Fixed in: 1.21.0
View patch
oraclepatch availablevia nvd_reference
View patch
power_bipatch availablevia llm_extracted
Fixed in: 1.20.1
View patch
redhatpatch availablevia redhat_api
Product: 3scale API Management 2.11 on RHEL 8Fixed in: 3scale-amp2/toolbox-rhel8:1.6.0-7
View patch
redhatpatch availablevia redhat_api
Product: 3scale API Management 2.11 on RHEL 8Fixed in: 3scale-amp2/zync-rhel8:1.14.0-3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Advanced Cluster Management for Kubernetes 2.1 for RHEL 8Fixed in: rhacm2/acm-must-gather-rhel8:v2.1.11-2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Advanced Cluster Management for Kubernetes 2.3 for RHEL 7Fixed in: rhacm2/management-ingress-rhel7:v2.3.3-3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Ansible Tower 3.8 for RHEL 7Fixed in: ansible-tower-38/ansible-tower-rhel7:3.8.4-1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Automation Hub 4.2 for RHEL 7Fixed in: automation-hub-0:4.2.5-1.el7pc
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Automation Hub 4.2 for RHEL 7Fixed in: python-galaxy-ng-0:4.2.5-2.el7pc
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Automation Hub 4.2 for RHEL 7Fixed in: python-pulpcore-0:3.7.6-1.el7pc
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Automation Hub 4.2 for RHEL 8Fixed in: automation-hub-0:4.2.5-1.el8pc
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Automation Hub 4.2 for RHEL 8Fixed in: python-galaxy-ng-0:4.2.5-2.el8pc
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Automation Hub 4.2 for RHEL 8Fixed in: python-pulpcore-0:3.7.6-1.el8pc
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: nginx:1.18-8040020210526100943.522a0ee4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: nginx:1.16-8040020210526102347.522a0ee4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: nginx:1.20-8050020211221125012.c5368500
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.1 Extended Update SupportFixed in: nginx:1.16-8010020210526102741.c27ad7f8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.2 Extended Update SupportFixed in: nginx:1.16-8020020210526102648.4cda2c84
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7Fixed in: rh-nginx118-nginx-1:1.18.0-3.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7Fixed in: rh-nginx116-nginx-1:1.16.1-6.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUSFixed in: rh-nginx118-nginx-1:1.18.0-3.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUSFixed in: rh-nginx116-nginx-1:1.16.1-6.el7
View patch
redhatpatch availablevia redhat_api
Product: 3scale API Management 2.11 on RHEL 8Fixed in: 3scale-amp2/apicast-gateway-rhel8:1.20.0-6
View patch
redhatpatch availablevia redhat_api
Product: 3scale API Management 2.11 on RHEL 7Fixed in: 3scale-amp2/system-rhel7:1.15.0-8
View patch
redhatpatch availablevia redhat_api
Product: 3scale API Management 2.11 on RHEL 7Fixed in: 3scale-amp2/memcached-rhel7:1.4.16-38
View patch
redhatpatch availablevia redhat_api
Product: 3scale API Management 2.11 on RHEL 7Fixed in: 3scale-amp2/3scale-rhel7-operator:1.14.0-4
View patch
redhatpatch availablevia redhat_api
Product: 3scale API Management 2.11 on RHEL 7Fixed in: 3scale-amp2/3scale-rhel7-operator-metadata:2.11.0-16
View patch
redhatpatch availablevia redhat_api
Product: 3scale API Management 2.11 on RHEL 8Fixed in: 3scale-amp2/backend-rhel8:1.14.0-3
View patch
redhatpatch availablevia redhat_api
Product: 3scale API Management 2.11 on RHEL 7Fixed in: 3scale-amp2/apicast-rhel7-operator-metadata:2.11.0-9
View patch
redhatpatch availablevia redhat_api
Product: 3scale API Management 2.11 on RHEL 7Fixed in: 3scale-amp2/apicast-rhel7-operator:1.14.0-3
View patch
terraformpatch availablevia llm_extracted
Fixed in: 1.21.0
View patch
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: nginx:1.14/nginx

Vendor Advisories (10)

microsoft2021-Jun/CVE-2021-23017Important

A security issue in nginx resolver was identified which might allow an attacker who is able to forge UDP packets from the DNS server to cause 1-byte memory overwrite resulting in worker process crash or potential other impact.

Jun 8, 2021
redhatCVE-2021-23017Important

nginx: Off-by-one in ngx_resolver_copy() when labels are followed by a pointer to a root domain name

May 25, 2021
dfinityllm-dfinity-7df11d2d0d88a2f5MEDIUM

1-byte memory overwrite in resolver

Jan 1, 2021
power_billm-power_bi-3b0b7437da3aa0deMEDIUM

1-byte memory overwrite in resolver

Jan 1, 2021
opensshllm-openssh-10dbf95c1473333eMEDIUM

1-byte memory overwrite in resolver

Jan 1, 2021
liferayllm-liferay-05361178f391f994MEDIUM

1-byte memory overwrite in resolver

Jan 1, 2021
jfrogllm-jfrog-84ea3ac3fdce1df8MEDIUM

1-byte memory overwrite in resolver

Jan 1, 2021
dahuallm-dahua-5ce839bbec1f0dc7MEDIUM

1-byte memory overwrite in resolver

terraformllm-terraform-a1778cbd6e919dc9MEDIUM

1-byte memory overwrite in resolver

netgearllm-netgear-5385c33c9edaaba0MEDIUM

1-byte memory overwrite in resolver

References

mailman.nginx.org / pipermail/nginx-announce/2021/000300.html
Mailing ListPatchVendor Advisory
packetstormsecurity.com / files/167720/Nginx-1.20.0-Denial-Of-Service.html
Third Party AdvisoryVDB Entry
lists.apache.org / thread.html/r37e6b2165f7c910d8e15fd54f4697857619ad2625f56583802004009%40%3Cnotifications.apisix.apache.org%3E
lists.apache.org / thread.html/r4d4966221ca399ce948ef34884652265729d7d9ef8179c78d7f17e7f%40%3Cnotifications.apisix.apache.org%3E
lists.apache.org / thread.html/r6fc5c57b38e93e36213e9a18c8a4e5dbd5ced1c7e57f08a1735975ba%40%3Cnotifications.apisix.apache.org%3E
lists.apache.org / thread.html/rf232eecd47fdc44520192810560303073cefd684b321f85e311bad31%40%3Cnotifications.apisix.apache.org%3E
lists.apache.org / thread.html/rf318aeeb4d7a3a312734780b47de83cefb7e6995da0b2cae5c28675c%40%3Cnotifications.apisix.apache.org%3E
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/7SFVYHC7OXTEO4SMBWXDVK6E5IMEYMEE
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/GNKOP2JR5L7KCIZTJRZDCUPJTUONMC5I
security.netapp.com / advisory/ntap-20210708-0006
Third Party Advisory
support.f5.com / csp/article/K12331123%2C
oracle.com / security-alerts/cpuapr2022.html
PatchThird Party Advisory
oracle.com / security-alerts/cpujan2022.html
PatchThird Party Advisory
oracle.com / security-alerts/cpuoct2021.html
PatchThird Party Advisory