← Back to browse · API

CVE-2017-20005

Severity
CRITICAL
CVSS
9.8
EPSS
0.03285
Risk score
40.35
CISA KEV
No
PoC
No
Published
2021-06-06
Modified
2025-12-05
First seen
2026-08-07
Aliases
EUVD-2017-11020, GHSA-6G54-R3Q8-8JVQ
Products
n/a:n/a n/a
Sources
euvd EUVD-2017-11020

Description

NGINX before 1.13.6 has a buffer overflow for years that exceed four digits, as demonstrated by a file with a modification date in 1969 that causes an integer overflow (or a false modification date far in the future), when encountered by the autoindex module.

References