Intel

AIKIDO-2026-436623

nginx is vulnerable to Use-After-Free

Use-After-Free Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published 3 days ago

72

High Risk

This Affects:

OSnginx
1.9.5 - 1.31.4
Fixed in 1.31.5
Are you affected? Scan for Free

TL;DR

When nginx proxies a response with buffering enabled to an HTTP/2 client, an error while writing the buffered response to that client can cause internal response buffers that are still referenced by the HTTP/2 output queue to be prematurely returned to the free list and reused or released. The fix keeps buffers still referenced by the downstream HTTP/2 output queue from being force-recycled on a downstream write error.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and run nginx as a reverse or gRPC proxy with response buffering enabled (the default) while serving clients over HTTP/2.

Background info

nginx is vulnerable to Use-After-Free in versions 1.9.5 - 1.31.4.

How to fix this

Upgrade the nginx library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform