Nginx maintains a focused but widely embedded web server and application platform whose vulnerabilities, despite a narrow product portfolio, carry outsized significance due to the vendor's prominence in internet-facing infrastructure and reverse-proxy deployments. The vendor's disclosures skew toward serious outcomes and frequently acquire public exploit code; recurring weakness classes including buffer-boundary issues, path traversal, and improper exception handling reflect the parsing and access-control challenges inherent to a high-performance HTTP handler. Defenders should prioritize Nginx advisories for internet-reachable instances and treat the web server tier as a consistent patching surface; live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nginx over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-3898MEDIUM Directory traversal vulnerability in src/http/modules/ngx_http_dav_module.c in nginx (aka Engine X) before 0.7.63, and 0.8.x before 0.8.17, allows remote authenticated users to cre | Nov 24, 2009 | 4.9 | 33 | NO | YES |
CVE-2021-46461CRITICAL njs through 0.7.0, used in NGINX, was discovered to contain an out-of-bounds array access via njs_vmcode_typeof in /src/njs_vmcode.c. | Feb 14, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-35173HIGH An issue was discovered in Nginx NJS v0.7.5. The JUMP offset for a break instruction was not set to a correct offset during code generation, leading to a segmentation violation. | Aug 18, 2022 | 7.5 | 25 | NO | NO |
CVE-2009-3896MEDIUM src/http/ngx_http_parse.c in nginx (aka Engine X) 0.1.0 through 0.4.14, 0.5.x before 0.5.38, 0.6.x before 0.6.39, 0.7.x before 0.7.62, and 0.8.x before 0.8.14 allows remote attacke | Nov 24, 2009 | 5.0 | 20 | NO | NO |
CVE-2022-30503MEDIUM Nginx NJS v0.7.2 was discovered to contain a segmentation violation in the function njs_set_number at src/njs_value.h. | Jun 2, 2022 | 5.5 | 19 | NO | NO |
CVE-2022-29779MEDIUM Nginx NJS v0.7.2 was discovered to contain a segmentation violation in the function njs_value_own_enumerate at src/njs_value.c. | Jun 2, 2022 | 5.5 | 19 | NO | NO |
CVE-2022-29780MEDIUM Nginx NJS v0.7.2 was discovered to contain a segmentation violation in the function njs_array_prototype_sort at src/njs_array.c. | Jun 2, 2022 | 5.5 | 16 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nginx.
Media articles that mention a CVE ID that affects a product developed by Nginx — matched by CVE ID, not by vendor name.