CVE-2020-21699: Alibaba Tengine

High severity, CVSS 7.5. EPSS: 0.8% chance of exploitation in the next 30 days.

The web server Tengine 2.2.2 developed in the Nginx version from 0.5.6 thru 1.13.2 is vulnerable to an integer overflow vulnerability in the nginx range filter module, resulting in the leakage of potentially sensitive information triggered by specially crafted requests.

Affected products

  • Alibaba Tengine: version 2.2.2 only

Published 2023-08-22. Last modified 2026-06-17.