nginx 1.25

Status EOLSupport 2023-05 – 2024-05Latest 1.25.5Vulnerabilities 16← All nginx versions
High 8.2 Unfixed
2026-03-24≤ 1.25.5

NGINX ngx_http_dav_module vulnerability

High 7.8 Unfixed
2026-03-24≤ 1.25.5

NGINX ngx_http_mp4_module vulnerability

High 7.8 Unfixed
2026-03-24≤ 1.25.5

NGINX ngx_http_mp4_module vulnerability

High 7.5 Unfixed
2026-03-24≤ 1.25.5

NGINX ngx_mail_auth_http_module vulnerability

High 7.5
2024-02-14< 1.25.4

NGINX HTTP/3 QUIC vulnerability

High 7.5
2024-02-14< 1.25.4

NGINX HTTP/3 QUIC vulnerability

KEV Unfixed
2023-10-10≤ 1.25.2

HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack)

Medium 6.5
2024-05-29≥ 1.25.0 and ≤ 1.25.5

NGINX HTTP/3 QUIC vulnerability

Medium 5.9 Unfixed
2026-02-04≤ 1.25.5

NGINX vulnerability

Medium 5.3
2024-05-29≥ 1.25.0 and ≤ 1.25.5

NGINX HTTP/3 QUIC vulnerability

Medium 5.3
2024-05-29≥ 1.25.0 and ≤ 1.25.5

NGINX HTTP/3 QUIC vulnerability

Medium 4.8
2024-05-29≥ 1.25.0 and ≤ 1.25.5

NGINX HTTP/3 QUIC vulnerability

Medium 4.7 Unfixed
2024-08-14≤ 1.25.5

NGINX MP4 module vulnerability

Medium 4.3 Unfixed
2025-02-05≤ 1.25.5

TLS Session Resumption Vulnerability

Low 3.7 Unfixed
2026-03-24≤ 1.25.5

NGINX ngx_mail_proxy_module vulnerability

Low 3.7 Unfixed
2025-08-13≤ 1.25.5

NGINX ngx_mail_smtp_module vulnerability