Sceawere

Vulnerability Detail

CVE-2026-105766UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Nginx Insecure Redirect Vulnerability

Vulnerability Metadata

Severity
Low
Score / CVSS
3.1
Creation Date
1d ago
Vendor
Chainguard
Product
Chainguard Academy (edu)
Attack Type
CWE-319 Cleartext Transmission of Sensitive Information
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N
Attack Complexity
HIGH

Narrative and Response

Description

Use of the backend-facing $scheme variable in the trailing-slash directory redirect in nginx.conf of Chainguard Academy (edu) from commit 0b75ff98057f69b044a3e7194e428066ac5ad0d4 before commit 93dc0e50739c225f5aee2e803800a47fc0feb906 allows an on-path network attacker to read or modify documentation content served to a victim via an HTTPS request for a slashless directory path, because TLS terminates at the load balancer in front of Nginx and the resulting 301 response redirects the client to a plaintext http:// URL. Browsers that ship the HSTS preload list are not affected, because the .dev top-level domain is preloaded; clients that do not enforce HSTS, such as command-line HTTP clients and scripts that follow redirects, are affected.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "3.1",
  "pubDate": "2026-10-05T20:17:20.620Z",
  "pubdate": "2026-10-05T20:17:20.620Z",
  "executiveSummary": "This vulnerability involves an insecure HTTP redirection mechanism within the nginx.conf configuration of the Chainguard Academy (edu) repository.\nThe flaw stems from the improper use of the $scheme variable when handling trailing-slash directory redirects in an environment where TLS termination occurs at an upstream load balancer.\nThis configuration error causes the application to issue 301 Moved Permanently redirects to unencrypted http:// URLs, despite the original request being made over HTTPS.\nAn on-path network attacker can intercept these plaintext redirects to conduct man-in-the-middle (MITM) attacks, potentially leading to the interception or manipulation of documentation content served to clients.\nThe impact is primarily restricted to non-HSTS compliant clients, such as command-line tools or legacy scripts, as modern web browsers rely on the .dev TLD HSTS preload list for protection.\nThe vulnerability affects commit range 0b75ff98057f69b044a3e7194e428066ac5ad0d4 through 93dc0e50739c225f5aee2e803800a47fc0feb906.",
  "technicalDetails": "The root cause of this vulnerability is the reliance on the Nginx $scheme variable within the configuration block responsible for trailing-slash redirection. In architectures where TLS is terminated at a load balancer or reverse proxy, the traffic reaching the Nginx backend is often forwarded as plaintext HTTP.\nWhen a user requests a directory path without a trailing slash, Nginx automatically triggers a redirect to the version with the slash. Because Nginx sees the incoming request from the load balancer as HTTP, the $scheme variable resolves to 'http'. Consequently, Nginx constructs a Location header using 'http://' instead of preserving the 'https://' scheme initiated by the end-user.\nAn on-path network attacker, positioned between the client and the infrastructure, can observe these unencrypted 301 redirects. If the client agent does not enforce HSTS (HTTP Strict Transport Security), it will follow the redirect to the plaintext HTTP URL provided by the server.\nThis behavior exposes the communication to interception, modification, or injection of content. In the context of Chainguard Academy, this permits the unauthorized modification of documentation content as it is delivered to the client, undermining the integrity of the served information.\nThe attack flow follows these steps: 1) The client sends an HTTPS request to a slashless directory path. 2) The load balancer terminates TLS and forwards the request to Nginx via HTTP. 3) Nginx identifies the need for a directory redirect. 4) The $scheme variable, interpreted as 'http', causes Nginx to return a 301 response with an insecure Location header. 5) The client agent, if not protected by HSTS, follows the insecure redirect to an attacker-controllable plaintext connection.\nWhile the .dev TLD is included in the HSTS preload list—rendering most modern browsers immune to this specific redirect manipulation—automated systems, CLI utilities, and legacy HTTP clients that ignore HSTS headers or preload lists remain vulnerable to this redirection to plaintext."
}
CVE-2026-105766: Nginx Insecure Redirect Vulnerability (LOW Severity, CVSS: 3.1) | Sceawere