The $uri$args concatenation in nginx configuration file...
High severity
Unreviewed
Published
Jan 29, 2026
to the GitHub Advisory Database
•
Updated Jan 29, 2026
Description
Published by the National Vulnerability Database
Jan 29, 2026
Published to the GitHub Advisory Database
Jan 29, 2026
Last updated
Jan 29, 2026
The $uri$args concatenation in nginx configuration file present in Open Security Issue Management (OSIM) prior v2025.9.0 allows path traversal attacks via query parameters.
References