CVE-2019-7401: F5 Nginx Unit

Critical severity, CVSS 9.8. EPSS: 2.9% chance of exploitation in the next 30 days.

NGINX Unit before 1.7.1 might allow an attacker to cause a heap-based buffer overflow in the router process with a specially crafted request. This may result in a denial of service (router process crash) or possibly have unspecified other impact.

Affected products

  • F5 Nginx Unit: from 0.3, before 1.7.1 (fixed in 1.7.1)

Published 2019-02-08. Last modified 2026-06-17.