NginxProxyManager / NginxProxyManager/nginx-proxy-manager
[Security] Nginx Config Injection via Unvalidated forward_host Field
Open
Nobody has claimed this yet.
bug
- Dominant language
- TypeScript
- Stars
- 34.2k
- Forks
- 3.9k
- Avg merge
- 21h 12m
- Merged PRs (30d)
- 20
Description
Hi, is there a place for me to report a security vulnerability? The security advisory link is down.
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
The issue only reports that the security advisory link is down and asks where to report a vulnerability; no file, test, or entry point is identified. Check the repository's current security-reporting path first, then confirm that contributors can reach a working advisory or reporting channel.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- nginx
- Domain
- security
- Issue type
- Bug
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Active
- Clarity
- Needs clarification
- Newbie friendliness
- 35/100