A vulnerability exists in the ngx_http_scgi_module and ngx_http_uwsgi_module modules that may result in excessive memory allocation or an over-read of data. When scgi_pass or uwsgi_pass is configured, an unauthenticated attacker with man-in-the-middle (MITM) ability to control responses from an upstream server may be able to read the memory of the NGINX worker process or restart it. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
We have discovered 2,703,794 live websites that are affected by CVE-2026-42946.
| Product | |
| Category | Web Servers |
| Vulnerable Domains | 2,703,794 live websites (92% of Nginx install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 231 versions ( 97% of all versions) |
| 769,353 websites | |
| 494,070 websites | |
| 279,306 websites | |
| 155,309 websites | |
| 141,961 websites | |
| 104,480 websites | |
| 85,718 websites | |
| 61,153 websites | |
| 47,373 websites | |
| 47,286 websites |
| .com | 1,081,445 websites |
| .ru | 473,892 websites |
| .org | 111,273 websites |
| .net | 99,218 websites |
| .de | 61,884 websites |
| .cn | 61,705 websites |
| .co.uk | 58,974 websites |
| .com.br | 55,066 websites |
| .it | 41,120 websites |
| .cz | 29,382 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ************.org | *** | ||
| *****.org | *** | ||
| ******.com | *** | ||
| ****.*********.com | *** | ||
| ******.de | *** | ||
| ****.******.org | *** | ||
| **.*****.com | *** | ||
| ********.**************.com | *** | ||
| ***.**.**.com | *** | ||
| *******.com | *** |
FAQ