Exposure of Documentation Content in Chainguard Academy due to Nginx Configuration Flaw
CVE-2026-105766

2.3LOW

Key Information:

Vendor

Chainguard

Vendor
CVE Published:
5 October 2026

What is CVE-2026-105766?

A configuration issue in the Chainguard Academy's Nginx server allows an on-path network attacker to manipulate the content delivered to users. This issue arises when the backend-facing $scheme variable is improperly used during redirection, leading to plaintext HTTP redirects. As a result, users attempting to access documentation without enforced HSTS may unknowingly expose their requests to interception, exposing them to potential exploitation.

Affected Version(s)

Chainguard Academy (edu) 0b75ff98057f69b044a3e7194e428066ac5ad0d4 < 93dc0e50739c225f5aee2e803800a47fc0feb906

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Matthew Helmke (https://github.com/matthewhelmke)
SunnyR (https://github.com/SunnyR)
Chainguard (https://chainguard.dev)
.