FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

Angie -- multiple vulnerabilities

Affected packages
angie < 1.12.1

Details

VuXML ID 347fe124-8f53-11f1-9f4f-3c7c3fba4204
Discovery 2026-07-17
Entry 2026-08-03

The Angie Software Team reports:

When evaluating a string expression in which unnamed capture variables ($1, $2, etc.) preceded a map directive variable whose value is determined by a regular expression, or when using a non-cacheable (volatile) map directive variable whose key contained a capture variable also used in the value of the same directive, worker process memory corruption or a worker process crash could occur (CVE-2026-42533); the fix was ported from nginx 1.31.3.

When using the slice directive or background cache update, if unnamed capture variables ($1, $2, etc.) were used together with a non-cacheable (volatile) map directive variable with a regular expression, the value of an unnamed capture variable could contain arbitrary bytes from worker process memory, or a worker process crash could occur (CVE-2026-60005); the fix was ported from nginx 1.31.3.

When using the SSI module with unbuffered proxying, worker process memory corruption or a worker process crash could occur (CVE-2026-56434); the fix was ported from nginx 1.31.3.

References

CVE Name CVE-2026-42533
CVE Name CVE-2026-56434
CVE Name CVE-2026-60005
URL https://nvd.nist.gov/vuln/detail/CVE-2026-42533
URL https://nvd.nist.gov/vuln/detail/CVE-2026-56434
URL https://nvd.nist.gov/vuln/detail/CVE-2026-60005