Tengine Project develops a web server platform derived from Nginx that operates in a narrow but specialized market segment, with observed vulnerabilities clustering around the Tengine product itself. The durable signal centers on classic buffer-overflow conditions arising from input-size validation issues, a weakness class characteristic of native-code web servers handling variable-length requests and headers. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tengine Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-28759MEDIUM The serializer module in OAID Tengine lite-v1.0 has a Buffer Overflow and crash. NOTE: another person has stated "I don't think there is an proof of overflow so far. | Dec 26, 2020 | 5.5 | 16 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tengine Project.
Media articles that mention a CVE ID that affects a product developed by Tengine Project — matched by CVE ID, not by vendor name.