Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2016-0746

27
FAUCET Score

CVE-2016-0746 is a critical use-after-free vulnerability in the NGINX resolver (versions 0.6.18 through 1.8.0 and 1.9.x before 1.9.10) that allows remote attackers to cause a denial of service or potentially other impacts through crafted DNS responses, specifically during CNAME processing. With a CVSS score of 9.8, this vulnerability is easily exploitable over the network with no user interaction, leading to high impacts on confidentiality, integrity, and availability. While no public exploit code or active exploitation is reported, its high EPSS and FAUCET Risk Score, along with community discussion and media coverage, indicate significant concern.

Impacted Technologies

VendorProductVersion(s)CPE
>= 0.6.18, <= 1.8.0CPE matchmatch criteria
cpe:2.3:a:f5:nginx:*:*:*:*:*:*:*:*
>= 1.9.0, < 1.9.10CPE matchmatch criteria
cpe:2.3:a:f5:nginx:*:*:*:*:*:*:*:*
14.04CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:*
15.10CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:15.10:*:*:*:*:*:*:*
7.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.8CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
8.63%
Probability of exploitation in next 30 days
EPSS Percentile
94.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.0862 is in the 90th percentile among its peer group of 36,829 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (16)

netgearpatch availablevia llm_extracted
Fixed in: 1.9.10+, 1.8.1+
opensshpatch availablevia llm_extracted
Fixed in: 1.9.10
View patch
power_bipatch availablevia llm_extracted
Fixed in: 1.8.1
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 6.6 EUSFixed in: rh-nginx18-nginx-1:1.8.1-1.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUSFixed in: rh-nginx18-nginx-1:1.8.1-1.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.1 EUSFixed in: rh-nginx18-nginx-1:1.8.1-1.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.2 EUSFixed in: rh-nginx18-nginx-1:1.8.1-1.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7Fixed in: rh-nginx18-nginx-1:1.8.1-1.el7
View patch
redhatpatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 6Fixed in: rh-nginx18-nginx-1:1.8.1-1.el6
View patch
terraformpatch availablevia llm_extracted
Fixed in: 1.9.10
dahuavendor investigatingvia llm_extracted
Fixed in: 1.8.1+
dfinityvendor investigatingvia llm_extracted
Fixed in: 1.9.10
jfrogvendor investigatingvia llm_extracted
Fixed in: 1.9.10
liferayvendor investigatingvia llm_extracted
Fixed in: 1.8.1
redhatend of lifevia redhat_api
Product: Red Hat Software CollectionsFixed in: nginx16-nginx

Vendor Advisories (9)

redhatCVE-2016-0746Moderate

nginx: use-after-free during CNAME response processing in resolver

Jan 26, 2016
opensshllm-openssh-8d4e9e32895b8c8aMEDIUM

Use-after-free during CNAME response processing in resolver

Jan 1, 2016
dfinityllm-dfinity-6c6b84445a3e3936MEDIUM

Use-after-free during CNAME response processing in resolver

Jan 1, 2016
power_billm-power_bi-8a760420ac2b4cb1MEDIUM

Use-after-free during CNAME response processing in resolver

Jan 1, 2016
liferayllm-liferay-b75e34f3a73fab62MEDIUM

Use-after-free during CNAME response processing in resolver

Jan 1, 2016
jfrogllm-jfrog-2c20ebe08d96aecdMEDIUM

Use-after-free during CNAME response processing in resolver

Jan 1, 2016
dahuallm-dahua-d9ebd00fb91c8b08MEDIUM

Use-after-free during CNAME response processing in resolver

terraformllm-terraform-32ab559044b76d47MEDIUM

Use-after-free during CNAME response processing in resolver

netgearllm-netgear-b9accdd0ffabbdeeMEDIUM

Use-after-free during CNAME response processing in resolver

References

lists.opensuse.org / opensuse-updates/2016-02/msg00042.html
Mailing ListThird Party Advisory
mailman.nginx.org / pipermail/nginx/2016-January/049700.html
Vendor Advisory
access.redhat.com / errata/RHSA-2016:1425
Third Party Advisory
bto.bluecoat.com / security-advisory/sa115
Third Party Advisory
bugzilla.redhat.com / show_bug.cgi
Issue TrackingPatchThird Party Advisory
seclists.org / fulldisclosure/2021/Sep/36
Mailing ListThird Party Advisory
security.gentoo.org / glsa/201606-06
Third Party Advisory
support.apple.com / kb/HT212818
Third Party Advisory
debian.org / security/2016/dsa-3473
Third Party Advisory
securitytracker.com / id/1034869
Third Party AdvisoryVDB Entry
ubuntu.com / usn/USN-2892-1
Third Party Advisory