CVE-2026-60005

NGINX ngx_http_slice_module vulnerability

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module. When the slice directive and unnamed regex captures are configured or when a background cache update happens, unauthenticated attackers can send requests that may cause uninitialized memory access in the NGINX worker process, leading to limited disclosure of memory or a restart. Impact: This vulnerability may allow remote, unauthenticated attackers to have limited control to disclose memory contents or restart the NGINX worker process. There is no control plane exposure; this is a data plane issue only. Note: The ngx_http_slice_module module is not enabled by default; it's enabled with the --with-http_slice_module configuration parameter. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.


We have discovered 2,423,045 live websites that are affected by CVE-2026-60005.

Run a Free Instant Scan




Affected Software

Product  Nginx
Category Web Servers
Vulnerable Domains2,423,045 live websites (83% of Nginx install base)
Vulnerable Versions
  • from 1.15.8 through 1.30.4
  • from 1.31.2 through 1.31.3
Vulnerable Versions Count85 versions ( 36% of all versions)


Common Weakness Enumeration

CWE-908 Use of Uninitialized Resource



Details

  • Published - Jul 15, 2026
  • Updated - Jul 15, 2026

Credits

  • F5 (finder)

Website Distribution by Country

Number of websites using CVE-2026-60005
United States631,243 websites



Russia569,054 websites
British Virgin Islands247,610 websites
Germany136,924 websites
China115,365 websites
GB100,322 websites
France73,849 websites
Netherlands47,065 websites
Brazil44,630 websites
Italy42,496 websites

Website Distribution by TLD

Number of websites using CVE-2026-60005
.com934,635 websites
.ru472,314 websites
.org101,970 websites
.net89,306 websites
.co.uk56,502 websites
.de54,651 websites
.cn53,449 websites
.com.br40,292 websites
.it36,891 websites
.nl30,159 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-60005

Top websites that are affected by CVE-2026-60005. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
************.org Singapore***
*.me British Virgin Islands***
*****.org United States***
******.com British Virgin Islands***
****.*********.com British Virgin Islands***
**.*****.com United States***
********.**************.com United States***
********.me British Virgin Islands***
*******.com United States***
*******.******.com United States***
See full domain list

FAQ

CVE-2026-60005 is Use of Uninitialized Resource in Nginx
A total of 2,423,045 websites have been identified as vulnerable to CVE-2026-60005, based on global website indexing conducted by WebTechSurvey.
The Nginx is affected by the CVE-2026-60005 vulnerability.
Nginx versions up to 1.31.3 are vulnerable to CVE-2026-60005.
CVE-2026-60005 is resolved in version 1.31.3 of Nginx.