NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module. When the slice directive and unnamed regex captures are configured or when a background cache update happens, unauthenticated attackers can send requests that may cause uninitialized memory access in the NGINX worker process, leading to limited disclosure of memory or a restart. Impact: This vulnerability may allow remote, unauthenticated attackers to have limited control to disclose memory contents or restart the NGINX worker process. There is no control plane exposure; this is a data plane issue only. Note: The ngx_http_slice_module module is not enabled by default; it's enabled with the --with-http_slice_module configuration parameter. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
We have discovered 2,423,045 live websites that are affected by CVE-2026-60005.
| Product | |
| Category | Web Servers |
| Vulnerable Domains | 2,423,045 live websites (83% of Nginx install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 85 versions ( 36% of all versions) |
| 631,243 websites | |
| 569,054 websites | |
| 247,610 websites | |
| 136,924 websites | |
| 115,365 websites | |
| 100,322 websites | |
| 73,849 websites | |
| 47,065 websites | |
| 44,630 websites | |
| 42,496 websites |
| .com | 934,635 websites |
| .ru | 472,314 websites |
| .org | 101,970 websites |
| .net | 89,306 websites |
| .co.uk | 56,502 websites |
| .de | 54,651 websites |
| .cn | 53,449 websites |
| .com.br | 40,292 websites |
| .it | 36,891 websites |
| .nl | 30,159 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ************.org | *** | ||
| *.me | *** | ||
| *****.org | *** | ||
| ******.com | *** | ||
| ****.*********.com | *** | ||
| **.*****.com | *** | ||
| ********.**************.com | *** | ||
| ********.me | *** | ||
| *******.com | *** | ||
| *******.******.com | *** |
FAQ