nginx: HTTP request smuggling in configurations with URL redirect used as error_page
Published Jan 9, 2020
5.3
MEDIUMCVSS 3.1
EPSS 14.96%
Description
NGINX before 1.17.7, with certain error_page configurations, allows HTTP request smuggling, as demonstrated by the ability of an attacker to read unauthorized web pages in environments where NGINX is being fronted by a load balancer.
Affected products
No data.
Configuration 3
- 14.04
Configuration 5
- n/a
No data.
Red Hat Ansible Tower 3.6 for RHEL 7
ansible-tower-36/ansible-tower:3.6.7-1
Fixed · RHSA-2021:0778
Red Hat Ansible Tower 3.7 for RHEL 7
ansible-tower-37/ansible-tower-rhel7:3.7.5-1
Fixed · RHSA-2021:0779
Red Hat Enterprise Linux 8
nginx:1.16-8030020201124104955.229f0a1c
Fixed · RHSA-2020:5495
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-nginx116-nginx-1:1.16.1-4.el7.1
Fixed · RHSA-2020:2817
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS
rh-nginx116-nginx-1:1.16.1-4.el7.1
Fixed · RHSA-2020:2817
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS
rh-nginx116-nginx-1:1.16.1-4.el7.1
Fixed · RHSA-2020:2817
CloudForms Management Engine 5
nginx
Will not fix
Red Hat Enterprise Linux 8
nginx:1.14/nginx
Will not fix
Red Hat Software Collections
rh-nginx110-nginx
Will not fix
Red Hat Software Collections
rh-nginx114-nginx
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Ansible Tower 3.6 for RHEL 7 | ansible-tower-36/ansible-tower:3.6.7-1 | Fixed | RHSA-2021:0778 |
| Red Hat Ansible Tower 3.7 for RHEL 7 | ansible-tower-37/ansible-tower-rhel7:3.7.5-1 | Fixed | RHSA-2021:0779 |
| Red Hat Enterprise Linux 8 | nginx:1.16-8030020201124104955.229f0a1c | Fixed | RHSA-2020:5495 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-nginx116-nginx-1:1.16.1-4.el7.1 | Fixed | RHSA-2020:2817 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS | rh-nginx116-nginx-1:1.16.1-4.el7.1 | Fixed | RHSA-2020:2817 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS | rh-nginx116-nginx-1:1.16.1-4.el7.1 | Fixed | RHSA-2020:2817 |
| CloudForms Management Engine 5 | nginx | Will not fix | n/a |
| Red Hat Enterprise Linux 8 | nginx:1.14/nginx | Will not fix | n/a |
| Red Hat Software Collections | rh-nginx110-nginx | Will not fix | n/a |
| Red Hat Software Collections | rh-nginx114-nginx | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Ansible Tower 3.5 and 3.6 are not vulnerable by default as are not using error_page variable in the nginx configuration. However, Ansible Tower 3.5 and 3.6 are distributing nginx 1.14 and 1.16 vulnerable versions as a dependency and configuration could be modified making it vulnerable. Red Hat CloudForms Management Engine 5.9 and 5.10 are not vulnerable by default as are not using error_page variable in the nginx configuration. However, both mentioned builds ships vulnerable nginx versions 1.10 and 1.14 respectively. CloudForms 5.11 does not use nginx directly hence it is not vulnerable. Red Hat Quay's configuration of nginx means it's not affected by this issue. It doesn't use error_page to do a 302 redirect. It's only use of error_page uses a named location ie: error_page 404 /404.html; location = /40x.html { } error_page 500 502 503 504 /50x.html; location = /50x.html { }
Red Hat mitigation
To mitigate this issue, use a named location instead of having the error_page handler do the redirect, this configuration is not vulnerable to request smuggling on all versions of NGINX we tested. server { listen 80; server_name localhost; error_page 401 @401; location / { return 401; } location @401 { return 302 http://example.org; } }
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
No CVSS v3.0 score for this CVE.
AV:N/AC:M/Au:N/C:P/I:N/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (52 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 14.96% (0.14961) | 96.61th | v5 (v2026.06.15) |
| Jun 15, 2026 | 14.96% (0.14961) | 96.28th | v5 (v2026.06.15) |
| May 14, 2026 | 69.32% (0.69321) | 98.67th | v4 (v2025.03.14) |
| Apr 17, 2026 | 70.83% (0.70833) | 98.70th | v4 (v2025.03.14) |
| Feb 9, 2026 | 69.74% (0.69737) | 98.62th | v4 (v2025.03.14) |
| Feb 4, 2026 | 68.43% (0.68429) | 98.56th | v4 (v2025.03.14) |
| Feb 1, 2026 | 64.22% (0.64217) | 98.40th | v4 (v2025.03.14) |
| Dec 28, 2025 | 68.87% (0.68870) | 98.56th | v4 (v2025.03.14) |
| Dec 27, 2025 | 74.52% (0.74525) | 98.81th | v4 (v2025.03.14) |
| Dec 24, 2025 | 68.87% (0.68870) | 98.56th | v4 (v2025.03.14) |
| Nov 21, 2025 | 67.67% (0.67669) | 98.50th | v4 (v2025.03.14) |
| Nov 18, 2025 | 45.83% (0.45826) | 97.48th | v4 (v2025.03.14) |
| Oct 28, 2025 | 67.67% (0.67669) | 98.50th | v4 (v2025.03.14) |
| Oct 27, 2025 | 73.53% (0.73533) | 98.75th | v4 (v2025.03.14) |
| Oct 5, 2025 | 67.67% (0.67669) | 98.52th | v4 (v2025.03.14) |
| Oct 4, 2025 | 63.73% (0.63735) | 98.35th | v4 (v2025.03.14) |
| Oct 1, 2025 | 64.76% (0.64764) | 98.41th | v4 (v2025.03.14) |
| Sep 13, 2025 | 70.23% (0.70235) | 98.63th | v4 (v2025.03.14) |
| Sep 4, 2025 | 71.47% (0.71473) | 98.67th | v4 (v2025.03.14) |
| Sep 1, 2025 | 67.61% (0.67609) | 98.53th | v4 (v2025.03.14) |
| Aug 11, 2025 | 71.47% (0.71473) | 98.65th | v4 (v2025.03.14) |
| Aug 4, 2025 | 75.07% (0.75073) | 98.82th | v4 (v2025.03.14) |
| Aug 1, 2025 | 71.68% (0.71680) | 98.67th | v4 (v2025.03.14) |
| Jul 30, 2025 | 75.07% (0.75073) | 98.82th | v4 (v2025.03.14) |
| Jun 4, 2025 | 68.56% (0.68560) | 98.50th | v4 (v2025.03.14) |
| Jun 1, 2025 | 64.36% (0.64363) | 98.33th | v4 (v2025.03.14) |
| May 3, 2025 | 69.47% (0.69475) | 98.55th | v4 (v2025.03.14) |
| May 1, 2025 | 64.36% (0.64363) | 98.33th | v4 (v2025.03.14) |
| Apr 20, 2025 | 68.56% (0.68560) | 98.48th | v4 (v2025.03.14) |
| Apr 6, 2025 | 64.11% (0.64111) | 98.30th | v4 (v2025.03.14) |
| Mar 30, 2025 | 65.20% (0.65201) | 98.34th | v4 (v2025.03.14) |
| Mar 29, 2025 | 72.58% (0.72575) | 98.37th | v4 (v2025.03.14) |
| Mar 28, 2025 | 64.60% (0.64601) | 98.31th | v4 (v2025.03.14) |
| Mar 27, 2025 | 72.58% (0.72575) | 98.64th | v4 (v2025.03.14) |
| Mar 20, 2025 | 64.60% (0.64601) | 98.34th | v4 (v2025.03.14) |
| Mar 19, 2025 | 72.58% (0.72575) | 98.67th | v4 (v2025.03.14) |
| Mar 17, 2025 | 64.60% (0.64601) | 98.30th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.27% (0.00273) | 68.86th | v3 (v2023.03.01) |
| Feb 8, 2024 | 0.28% (0.00277) | 67.30th | v3 (v2023.03.01) |
| Nov 30, 2023 | 0.28% (0.00277) | 64.74th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.20% (0.00203) | 56.47th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.54% (0.01537) | 74.52th | v2 (v2022.01.01) |
| Feb 23, 2023 | 1.54% (0.01537) | 74.48th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.54% (0.01537) | 72.41th | v2 (v2022.01.01) |
| Feb 23, 2022 | 27.13% (0.27133) | 95.84th | v2 (v2022.01.01) |
| Feb 4, 2022 | 19.29% (0.19291) | 93.75th | v2 (v2022.01.01) |
| Feb 3, 2022 | 10.80% (0.10798) | 87.90th | v1 |
| Jan 6, 2022 | 10.80% (0.10798) | 87.76th | v1 |
| Sep 22, 2021 | 2.63% (0.02627) | 79.27th | v1 |
| Sep 21, 2021 | 2.41% (0.02412) | 78.43th | v1 |
| Sep 1, 2021 | 2.20% (0.02196) | 77.49th | v1 |
| Apr 14, 2021 | 2.20% (0.02196) | 0.00th | v1 |
References (15)
- http://lists.opensuse.org/opensuse-security-announce/2020-02/msg00013.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://nginx.org/en/CHANGES x_refsource_MISCMitigationRelease NotesVendor Advisory
- http://seclists.org/fulldisclosure/2021/Sep/36 mailing-listx_refsource_FULLDISCMailing ListThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2019-20372 Vendor Advisory
- https://bertjwregeer.keybase.pub/2019-12-10%20-%20error_page%20request%20smuggling.pdf x_refsource_MISCExploitMitigationThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1790277 Issue Tracking
- https://duo.com/docs/dng-notes#version-1.5.4-january-2020 x_refsource_MISCRelease NotesThird Party Advisory
- https://github.com/kubernetes/ingress-nginx/pull/4859 x_refsource_MISCPatchThird Party Advisory
- https://github.com/nginx/nginx/commit/c1be55f97211d38b69ac0c2027e6812ab8b1b94e x_refsource_CONFIRMPatchVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-20372
- https://security.netapp.com/advisory/ntap-20200127-0003/ x_refsource_CONFIRMThird Party Advisory
- https://support.apple.com/kb/HT212818 x_refsource_CONFIRMThird Party Advisory
- https://usn.ubuntu.com/4235-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/4235-2/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2019-20372
Change history (0)
No recorded changes yet.