CVE-2026-105766
Received Received - Intake

Path Traversal in Chainguard Academy Documentation

Vulnerability report for CVE-2026-105766, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: 82cea9a6-e9e3-46fe-bdb0-3673de380178

Description

Use of the backend-facing $scheme variable in the trailing-slash directory redirect in nginx.conf of Chainguard Academy (edu) from commit 0b75ff98057f69b044a3e7194e428066ac5ad0d4 before commit 93dc0e50739c225f5aee2e803800a47fc0feb906 allows an on-path network attacker to read or modify documentation content served to a victim via an HTTPS request for a slashless directory path, because TLS terminates at the load balancer in front of Nginx and the resulting 301 response redirects the client to a plaintext http:// URL. Browsers that ship the HSTS preload list are not affected, because the .dev top-level domain is preloaded; clients that do not enforce HSTS, such as command-line HTTP clients and scripts that follow redirects, are affected.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-06
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Chainguard Chainguard Academy (edu) 0b75ff98057f69b044a3e7194e428066ac5ad0d4

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-319 The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves the misuse of the $scheme variable in nginx.conf of Chainguard Academy's documentation server. When a user requests a directory path without a trailing slash, the server incorrectly redirects them to an HTTP URL instead of HTTPS. This happens because the load balancer terminates TLS, and the backend Nginx uses the $scheme variable which defaults to http in this context.

Detection Guidance

To detect this vulnerability, inspect nginx configuration files for improper use of $scheme in redirect rules. Check for trailing-slash redirects that may downgrade HTTPS to HTTP. Use curl to test redirects: curl -I https://yourdomain.com/path/ without trailing slash. Look for 301 responses redirecting to http:// URLs. Verify query string handling with curl -v 'https://yourdomain.com/path?param=value' to check if parameters are preserved or duplicated.

Impact Analysis

An attacker on the network path can intercept and modify the plaintext HTTP redirect response, potentially redirecting victims to malicious sites or exposing sensitive documentation content. Users without HSTS enforcement (like scripts or CLI tools) are vulnerable, while browsers with HSTS preload lists are protected.

Compliance Impact

This vulnerability does not directly impact GDPR or HIPAA compliance as it involves a redirect issue in documentation content served over HTTP instead of HTTPS due to a misconfigured $scheme variable. The exposure is limited to plaintext HTTP requests for slashless directory paths, which may expose documentation content to on-path network attackers. No evidence suggests this affects protected health or personal data handling under these regulations.

Mitigation Strategies

Update Chainguard Academy (edu) to a commit after 93dc0e50739c225f5aee2e803800a47fc0feb906 to fix the trailing-slash directory redirect issue. Ensure TLS terminates at the backend server rather than a load balancer to prevent plaintext HTTP redirects.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105766. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart