Security Advisories#

This page consolidates the security vulnerabilities fixed in Angie products, so their status can be checked at a glance. Detailed descriptions of the fixes are available in the Angie and Angie PRO changelogs and in the Angie ADC changelog.

Reporting a Vulnerability#

If you believe you have found a security vulnerability in Angie, Angie PRO, Angie ADC, or ANIC, report it privately by emailing .

A report is easier to act on when it includes:

  • the product and its exact version;

  • the operating system or platform;

  • a minimal configuration fragment that reproduces the issue;

  • the steps to reproduce and the observed impact.

Please give the team the opportunity to investigate the report and release a fix before disclosing the issue publicly.

Fixed Vulnerabilities#

The table lists the fixed vulnerabilities and the Angie version where the fix first shipped. CVSS values are CVSS 3.1 base scores as published in the National Vulnerability Database.

CVE

CVSS

Description

Angie

CVE-2026-42533

8.1 (High)

Memory corruption or worker process crash in string expressions that combine unnamed capture variables with map variables

1.12.1

CVE-2026-60005

8.2 (High)

Disclosure of worker process memory via unnamed capture variables with slice or proxy_cache_background_update

1.12.1

CVE-2026-56434

6.5 (Medium)

Memory corruption or worker process crash in the SSI module with unbuffered proxying

1.12.1

CVE-2026-42055

8.1 (High)

Buffer overflow when proxying specially crafted requests to a gRPC backend

1.11.8

CVE-2026-48142

4.8 (Medium)

Out-of-bounds read during UTF-8 conversion with charset_map, disclosing worker process memory to the client

1.11.8

CVE-2026-9256

8.1 (High)

Worker process crash or potential code execution via nested PCRE captures in rewrite

1.11.6

CVE-2026-42945

8.1 (High)

Worker process crash or potential code execution via unnamed captures in rewrite replacement strings

1.11.5

CVE-2026-40701

4.8 (Medium)

Use-after-free in ssl_ocsp while processing DNS responses

1.11.5

CVE-2026-40460

6.5 (Medium)

Client IP address spoofing over HTTP/3, bypassing address-based restrictions

1.11.5

CVE-2026-42946

7.4 (High)

Excessive memory reads and disclosure when a man-in-the-middle attacker interferes with scgi_pass or uwsgi_pass

1.11.5

CVE-2026-42934

4.8 (Medium)

Out-of-bounds read during UTF-8 conversion with charset_map

1.11.5

CVE-2026-28755

5.4 (Medium)

TLS handshake with a client in the stream module could succeed despite OCSP rejecting the client certificate

1.11.4

CVE-2026-27654

8.2 (High)

Buffer overflow in the DAV module when handling COPY and MOVE requests in a location with alias

1.11.4

CVE-2026-27784

7.8 (High)

Worker process crash in the MP4 module on 32-bit platforms

1.11.4

CVE-2026-32647

7.8 (High)

Worker process crash in the MP4 module on a specially crafted file

1.11.4

CVE-2026-27651

7.5 (High)

Worker process crash in the mail proxy during CRAM-MD5 or APOP authentication retries

1.11.4

CVE-2026-28753

3.7 (Low)

Injection of PTR DNS record data into mail proxy authentication requests

1.11.4

CVE-2026-1642

5.9 (Medium)

Plaintext injection by a man-in-the-middle attacker before the TLS handshake with a proxied server

1.11.3

CVE-2025-53859

3.7 (Low)

Disclosure of worker process memory to the authentication server with the SMTP none method

1.10.3

CVE-2025-23419

4.3 (Medium)

TLSv1.3 session reuse across virtual servers could bypass client certificate verification

1.8.2

CVE-2024-7347

4.7 (Medium)

Worker process crash in the MP4 module on a specially crafted file

1.6.2

CVE-2024-32760

6.5 (Medium)

Worker process crash or memory disclosure via specially crafted QUIC sessions (HTTP/3)

1.5.2

CVE-2024-31079

4.8 (Medium)

Worker process crash or memory disclosure via specially crafted QUIC sessions (HTTP/3)

1.5.2

CVE-2024-35200

5.3 (Medium)

Worker process crash or memory disclosure via specially crafted QUIC sessions (HTTP/3)

1.5.2

CVE-2024-34161

5.3 (Medium)

Worker process crash or memory disclosure via specially crafted QUIC sessions (HTTP/3)

1.5.2

CVE-2024-24989

7.5 (High)

Worker process crash (segmentation fault) via specially crafted QUIC sessions (HTTP/3)

1.4.1

CVE-2023-44487

7.5 (High)

HTTP/2 Rapid Reset denial of service; additional stream limits (mitigation)

1.3.1

Not Affected#

Some vulnerabilities published for nginx do not apply to Angie: