nginx 1.13

Status EOLSupport 2017-04 – 2018-06Latest 1.13.12Vulnerabilities 21← All nginx versions
Critical 9.8
2021-06-06< 1.13.6

nginx: buffer overflow in ngx_gmtime() triggered by 5 digit years

High 8.2 Unfixed
2026-03-24≤ 1.13.12

NGINX ngx_http_dav_module vulnerability

High 7.8 Unfixed
2026-03-24≤ 1.13.12

NGINX ngx_http_mp4_module vulnerability

High 7.8 Unfixed
2026-03-24≤ 1.13.12

NGINX ngx_http_mp4_module vulnerability

High 7.7 Unfixed
2021-06-01≤ 1.13.12

nginx: Off-by-one in ngx_resolver_copy() when labels are followed by a pointer to a root domain name

High 7.5 Unfixed
2026-03-24≤ 1.13.12

NGINX ngx_mail_auth_http_module vulnerability

High 7.5
2017-07-13≤ 1.13.2

nginx: Integer overflow in nginx range filter module leading to memory disclosure

High 7.5 Unfixed
2018-11-07≤ 1.13.12

nginx: Excessive CPU usage via flaw in HTTP/2 implementation

High 7.5 Unfixed
2018-11-07≤ 1.13.12

nginx: Excessive memory consumption via flaw in HTTP/2 implementation

KEV Unfixed
2023-10-10≤ 1.13.12

HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack)

High 7.5 Unfixed
2019-08-13≤ 1.13.12

Some HTTP/2 implementations are vulnerable to resource loops, potentially leading to a denial of service

High 7.5 Unfixed
2019-08-13≤ 1.13.12

Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of service

High 7.4 Unfixed
2022-03-23≤ 1.13.12

ALPACA: Application Layer Protocol Confusion - Analyzing and Mitigating Cracks in TLS Authentication

High 7.1 Unfixed
2022-10-19≤ 1.13.12

NGINX ngx_http_mp4_module vulnerability CVE-2022-41742

Medium 6.5 Unfixed
2019-08-13≤ 1.13.12

Some HTTP/2 implementations are vulnerable to a header leak, potentially leading to a denial of service

Medium 6.1 Unfixed
2018-11-07≤ 1.13.12

nginx: Denial of service and memory disclosure via mp4 module

Medium 5.9 Unfixed
2026-02-04≤ 1.13.12

NGINX vulnerability

Medium 5.3 Unfixed
2020-01-09≤ 1.13.12

nginx: HTTP request smuggling in configurations with URL redirect used as error_page

Medium 4.7 Unfixed
2024-08-14≤ 1.13.12

NGINX MP4 module vulnerability

Low 3.7 Unfixed
2026-03-24≤ 1.13.12

NGINX ngx_mail_proxy_module vulnerability

Low 3.7 Unfixed
2025-08-13≤ 1.13.12

NGINX ngx_mail_smtp_module vulnerability