nginx 1.20

Status EOLSupport 2021-04 – 2022-05Latest 1.20.2Vulnerabilities 13← All nginx versions
High 8.2 Unfixed
2026-03-24≤ 1.20.2

NGINX ngx_http_dav_module vulnerability

High 7.8 Unfixed
2026-03-24≤ 1.20.2

NGINX ngx_http_mp4_module vulnerability

High 7.8 Unfixed
2026-03-24≤ 1.20.2

NGINX ngx_http_mp4_module vulnerability

High 7.7
2021-06-01< 1.20.1

nginx: Off-by-one in ngx_resolver_copy() when labels are followed by a pointer to a root domain name

High 7.5 Unfixed
2026-03-24≤ 1.20.2

NGINX ngx_mail_auth_http_module vulnerability

KEV Unfixed
2023-10-10≤ 1.20.2

HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack)

High 7.4 Unfixed
2022-03-23≤ 1.20.2

ALPACA: Application Layer Protocol Confusion - Analyzing and Mitigating Cracks in TLS Authentication

High 7.1 Unfixed
2022-10-19≤ 1.20.2

NGINX ngx_http_mp4_module vulnerability CVE-2022-41742

High 7.0 Unfixed
2022-10-19≤ 1.20.2

NGINX ngx_http_mp4_module vulnerability CVE-2022-41741

Medium 5.9 Unfixed
2026-02-04≤ 1.20.2

NGINX vulnerability

Medium 4.3 Unfixed
2025-02-05≤ 1.20.2

TLS Session Resumption Vulnerability

Low 3.7 Unfixed
2026-03-24≤ 1.20.2

NGINX ngx_mail_proxy_module vulnerability

Low 3.7 Unfixed
2025-08-13≤ 1.20.2

NGINX ngx_mail_smtp_module vulnerability