Skip to content

Hubble UI docker images has CVE-2026-42945 vulnerability #1106

Description

@danieltaylor-rgb

Hey folks - Wiz picked up a vulnerability in hubble-ui's docker image.

The package nginx version 1.29.8 was detected in APK package manager on a container image running Alpine 3.23.3 is vulnerable to CVE-2026-42945, which exists in versions >= 0.6.27, <= 1.30.0.
The vulnerability was found in the National Vulnerability Database (NVD) but CPE information was missing so Wiz manually mapped it to CPE cpe:2.3:a:f5:nginx_open_source and the reporting CNA has assigned it severity: High

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond its control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions