Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2016-4450

33
FAUCET Score

CVE-2016-4450 is a denial-of-service vulnerability affecting Nginx versions prior to 1.10.1 and 1.11.1, as well as various distributions including Canonical, Debian, and F5. A remote attacker can trigger a NULL pointer dereference and crash a worker process by sending a crafted request that involves writing a client request body to a temporary file. This vulnerability has a CVSS score of 7.5 (High), indicating a network-exploitable attack with low complexity and a high impact on availability. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or inclusion in CISA's KEV catalog, though it has received some community discussion and media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
14.04CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:*
15.10CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:15.10:*:*:*:*:*:*:*
16.04CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
>= 1.3.9, < 1.10.1CPE matchmatch criteria
cpe:2.3:a:f5:nginx:*:*:*:*:*:*:*:*
1.11.0CPE matchmatch criteria
cpe:2.3:a:f5:nginx:1.11.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
16.38%
Probability of exploitation in next 30 days
EPSS Percentile
96.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.1638 is in the 95th percentile among its peer group of 51,506 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (15)

dahuapatch availablevia llm_extracted
Fixed in: 1.10.1+
View patch
dfinitypatch availablevia llm_extracted
Fixed in: 1.11.1
View patch
jfrogpatch availablevia llm_extracted
Fixed in: 1.11.1
View patch
liferaypatch availablevia llm_extracted
Fixed in: 1.10.1
View patch
netgearpatch availablevia llm_extracted
Fixed in: 1.11.1+, 1.10.1+
View patch
opensshpatch availablevia llm_extracted
Fixed in: 1.11.1
View patch
power_bipatch availablevia llm_extracted
Fixed in: 1.10.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 6.6 EUSFixed in: rh-nginx18-nginx-1:1.8.1-1.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUSFixed in: rh-nginx18-nginx-1:1.8.1-1.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7Fixed in: rh-nginx18-nginx-1:1.8.1-1.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.1 EUSFixed in: rh-nginx18-nginx-1:1.8.1-1.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.2 EUSFixed in: rh-nginx18-nginx-1:1.8.1-1.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 6Fixed in: rh-nginx18-nginx-1:1.8.1-1.el6
View patch
terraformpatch availablevia llm_extracted
Fixed in: 1.11.1
View patch
redhatend of lifevia redhat_api
Product: Red Hat Software CollectionsFixed in: nginx16-nginx

Vendor Advisories (9)

redhatCVE-2016-4450Moderate

nginx: NULL pointer dereference while writing client request body

May 31, 2016
opensshllm-openssh-8a2315bafe5ff726MEDIUM

NULL pointer dereference while writing client request body

Jan 1, 2016
dfinityllm-dfinity-28109ee777261ad3MEDIUM

NULL pointer dereference while writing client request body

Jan 1, 2016
power_billm-power_bi-42ee5a2cec40541dMEDIUM

NULL pointer dereference while writing client request body

Jan 1, 2016
liferayllm-liferay-285ef1469e0998f5MEDIUM

NULL pointer dereference while writing client request body

Jan 1, 2016
jfrogllm-jfrog-ce14ca12fd230a22MEDIUM

NULL pointer dereference while writing client request body

Jan 1, 2016
dahuallm-dahua-7ee47e1fb18484afMEDIUM

NULL pointer dereference while writing client request body

terraformllm-terraform-30c41ef30084df33MEDIUM

NULL pointer dereference while writing client request body

netgearllm-netgear-432e19bb3b7a56ddMEDIUM

NULL pointer dereference while writing client request body

References

mailman.nginx.org / pipermail/nginx-announce/2016/000179.html
Vendor Advisory
access.redhat.com / errata/RHSA-2016:1425
Third Party Advisory
security.gentoo.org / glsa/201606-06
Third Party Advisory
debian.org / security/2016/dsa-3592
Third Party Advisory
securityfocus.com / bid/90967
Third Party AdvisoryVDB Entry
securitytracker.com / id/1036019
Third Party AdvisoryVDB Entry
ubuntu.com / usn/USN-2991-1
Third Party Advisory