A Critical Nginx Flaw and Who Is Actually Exposed

On July 15, F5 patched a critical vulnerability in Nginx, the web server behind a large share of the internet, that had been sitting in the code since 2011. It is rated 9.2 on the newer CVSS v4 scale, it needs no authentication, and a crafted HTTP request can crash a worker process or, in the wrong conditions, run … Continue reading A Critical Nginx Flaw and Who Is Actually Exposed