CVE-2026-56434

NGINX ngx_http_ssi_module vulnerability

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssi_module module. This vulnerability may exist when the Server-Side Includes (SSI), proxy_pass, and proxy_buffering off directives are configured. With this configuration, an unauthenticated attacker with man-in-the-middle (MITM) ability to control responses from an upstream server may be able to cause a use-after-free in the NGINX worker process. This issue may lead to limited modification of memory or a restart of the NGINX worker process. Impact: This vulnerability may allow remote attackers to have limited control to modify memory contents or restart the NGINX worker process. There is no control plane exposure; this is a data plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.


We have discovered 2,876,938 live websites that are affected by CVE-2026-56434.

Run a Free Instant Scan




Affected Software

Product  Nginx
Category Web Servers
Vulnerable Domains2,876,938 live websites (98% of Nginx install base)
Vulnerable Versions
  • from 0.8.11 through 1.30.4
  • from 1.31.2 through 1.31.3
Vulnerable Versions Count235 versions ( 99% of all versions)


Common Weakness Enumeration

CWE-416 Use After Free



Details

  • Published - Jul 15, 2026
  • Updated - Jul 15, 2026

Credits

  • F5 acknowledges p4p3r(@P4P3R-HAK)" of "싸이버원(CYBERONE) for bringing this issue to our attention and following the highest standards of coordinated disclosure. (reporter)

Website Distribution by Country

Number of websites using CVE-2026-56434
United States795,255 websites



Russia616,309 websites
British Virgin Islands279,504 websites
Germany160,712 websites
China142,712 websites
GB105,312 websites
France87,377 websites
Brazil61,545 websites
Netherlands52,091 websites
Italy47,663 websites

Website Distribution by TLD

Number of websites using CVE-2026-56434
.com1,112,005 websites
.ru573,940 websites
.org115,520 websites
.net102,537 websites
.de64,384 websites
.cn61,850 websites
.co.uk59,490 websites
.com.br55,354 websites
.it41,575 websites
.nl33,219 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-56434

Top websites that are affected by CVE-2026-56434. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
************.org Singapore***
*.me British Virgin Islands***
*****.org United States***
******.com British Virgin Islands***
****.*********.com British Virgin Islands***
******.de Germany***
****.******.org United States***
**.*****.com United States***
********.**************.com United States***
***.**.**.com China***
See full domain list

FAQ

CVE-2026-56434 is Use After Free in Nginx
A total of 2,876,938 websites have been identified as vulnerable to CVE-2026-56434, based on global website indexing conducted by WebTechSurvey.
The Nginx is affected by the CVE-2026-56434 vulnerability.
Nginx versions up to 1.31.3 are vulnerable to CVE-2026-56434.
CVE-2026-56434 is resolved in version 1.31.3 of Nginx.