Safeguard
Tag

nginx

Safeguard articles tagged "nginx" — guides, analysis, and best practices for software supply chain and application security.

12 articles

Container Security

CVE-2026-42945: A Buffer Overflow in NGINX's Rewrite Module Reaches Into Your Kubernetes Clusters (May 2026)

Disclosed May 17, 2026 with public PoC and in-the-wild activity, CVE-2026-42945 is a buffer overflow in NGINX's ngx_http_rewrite_module. It affects core NGINX and the ingress controllers that wrap it, putting cluster ingress in scope.

May 18, 202612 min read
Vulnerability Analysis

PHP-FPM/Nginx path disclosure RCE (CVE-2019-11043)

CVE-2019-11043 let attackers gain unauthenticated RCE on PHP-FPM/Nginx stacks via a PATH_INFO underflow. Here's the impact, timeline, and fixes.

Jan 17, 20267 min read
AppSec

Nginx Version Vulnerabilities: CVE Guide from 1.10 to 1.24

From the nginx 1.18.0 vulnerability set back to 1.10.3 and forward to 1.24.0: which CVEs actually apply to each version line, which need specific config to exploit, and where to upgrade.

Sep 11, 20256 min read
Security

nginx 1.22.1 Vulnerabilities: What Actually Affects You

Worried about nginx 1.22.1 vulnerabilities? Here is what genuinely affects this release, what does not, and how to decide whether you need to upgrade.

Sep 9, 20255 min read
Vulnerabilities

Nginx 1.18.0 Vulnerabilities: Audit and Upgrade Path

Nginx 1.18.0 left support in 2021, but not every scanner hit is exploitable — and many distro builds are already patched. How to audit what you actually run and get onto a supported line.

Aug 14, 20256 min read
Security

Is There an Nginx 1.18.0 Exploit? What the Known CVEs Actually Mean

Nginx 1.18.0 is an unmaintained stable release with real CVEs against it. Here is which flaws are genuinely exploitable, which need specific config, and how to upgrade.

May 27, 20255 min read
Security

Securing Nginx on AWS: The Webinar-Grade Hardening Checklist

Running Nginx on AWS pairs two of the most common infrastructure choices, and this is the hardening walkthrough we would give in a live AWS Nginx webinar.

May 6, 20256 min read
Security

nginx/1.18.0 (ubuntu): What the Server Banner Reveals and How to Reduce Risk

Seeing nginx/1.18.0 (ubuntu) in a Server header tells you the version, the packaging, and roughly the age of a deployment. Here is what that string implies for security and what to check before assuming you are exposed.

Feb 11, 20256 min read
Security

Nginx 1.14.2: Which Vulnerabilities Affect It and How to Upgrade

Nginx/1.14.2 is an end-of-life release carrying the resolver heap overwrite, HTTP/2 DoS flaws, and a request-smuggling bug. Here is what applies and the upgrade path.

Jan 28, 20255 min read
Security

Nginx and CVE-2023-44487: How to Fix HTTP/2 Rapid Reset

CVE-2023-44487, the HTTP/2 Rapid Reset attack, is a protocol-level DoS. Nginx resists it with default settings, but a loose keepalive config can still be abused. Here's the fix.

Jan 22, 20256 min read
Vulnerabilities

Nginx 1.20.1 Vulnerabilities: What to Patch

Nginx 1.20.1 fixed a real, exploitable DNS resolver bug — if you're still running an older 1.20.x or 1.19.x build, here's what the fix addressed and why it matters.

Feb 19, 20244 min read
Infrastructure Security

NGINX Security Configuration Guide for Production Deployments

NGINX powers a third of the internet. Its default configuration is optimized for getting started, not for production security. Here is the gap.

Jul 12, 20224 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.

nginx — Safeguard Blog