High [CVE-2026-60005] Memory disclosure and denial of service in ngx_http_slice_module
This high-severity Red Hat Linux advisory covers CVE-2026-60005 affecting Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9.
Aggregated and source-linked by VulniPulse. Data sources, validation and limitations.
VulniPulse record published Record updated
Android app · Google Play
Monitor future Red Hat Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Summary
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module.
When the slice directive and unnamed regex captures are configured or when a background cache update happens, unauthenticated attackers can send requests that may cause uninitialized memory access in the NGINX worker process, leading to limited disclosure of memory or a restart. There is no control plane exposure; this is a data plane issue only.
Note: The ngx_http_slice_module module is not enabled by default; it's enabled with the --with-http_slice_module configuration parameter. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Important: This vulnerability in NGINX's `ngx_http_slice_module` could lead to memory disclosure or denial of service. The impact on Red Hat products is reduced because the `ngx_http_slice_module` is not enabled by default.
Exploitation requires explicit configuration of the module with the `slice` directive and unnamed regex captures, or during a background cache update, limiting exposure in typical deployments. Red Hat severity: Important — CVSS 8.2 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H).
Weakness: CWE-824. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Discovery 2; Red Hat Hardened Images; Red Hat Lightspeed proxy 1.
Affected versions
No affected-version range was extracted from the source record. The vendor advisory is authoritative — check it before change work.
Official advisory · high-confidence parse· fetched 12 days ago·verify at source
- nginx-2:1.26.3-6.el10_2.6
- nginx:1.24-8100020260809162034.489197e6
- nginx-2:1.20.1-28.el9_8.5
- nginx:1.24-9080020260804072754.9
- nginx:1.26-9080020260803214158.9
- discovery/discovery-ui-rhel9:1788206196
- nginx-main-1.30.4-2.hum1
- RHSA-2026:59220
- RHSA-2026:59216
- RHSA-2026:59362
- RHSA-2026:59490
- RHSA-2026:59496
- RHSA-2026:61783
- RHSA-2026:46012
Official advisory · high-confidence parse· fetched 12 days ago·verify at source
Mitigation checklist
- To mitigate this issue, disable the ngx_http_slice_module entirely if it is not required. If the module must be used, avoid unnamed regex captures with the slice directive and explicitly disable proxy_cache_background_update. Reload or restart the NGINX service to apply these changes. Please note this may cause a brief service interruption.
Official advisory · high-confidence parse· fetched 12 days ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.