{"id":"CVE-2026-105766","title":"Use of the backend-facing $scheme variable in the trailing-slash directory redirect in nginx.conf of Chainguard Academy (edu) from commit 0b75ff98057f69b044a3e7194e428066ac5ad0d4 before commit 93dc0e50739c225f5aee2e803800a47fc0feb906 all…","summary":"Use of the backend-facing $scheme variable in the trailing-slash directory redirect in nginx.conf of Chainguard Academy (edu) from commit 0b75ff98057f69b044a3e7194e428066ac5ad0d4 before commit 93dc0e50739c225f5aee2e803800a47fc0feb906 all…","severity":"low","cvss":3.1,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N","cwe":["CWE-319"],"vendor":"Chainguard","product":"Chainguard Academy (edu)","affected":["academy_edu >= 0b75ff98057f69b044a3e7194e428066ac5ad0d4 < 93dc0e50739c225f5aee2e803800a47fc0feb906"],"published":"2026-10-05","updated":"2026-10-05","sourceUpdated":"2026-10-05T20:17:20.620","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-105766","references":[{"url":"https://github.com/chainguard-dev/edu/commit/93dc0e50739c225f5aee2e803800a47fc0feb906","label":"82cea9a6-e9e3-46fe-bdb0-3673de380178"},{"url":"https://github.com/chainguard-dev/edu/pull/3989","label":"82cea9a6-e9e3-46fe-bdb0-3673de380178"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-05T20:32:56.654Z","slug":"CVE-2026-105766","body":"## Overview\n\nUse of the backend-facing $scheme variable in the trailing-slash directory redirect in nginx.conf of Chainguard Academy (edu) from commit 0b75ff98057f69b044a3e7194e428066ac5ad0d4 before commit 93dc0e50739c225f5aee2e803800a47fc0feb906 allows an on-path network attacker to read or modify documentation content served to a victim via an HTTPS request for a slashless directory path, because TLS terminates at the load balancer in front of Nginx and the resulting 301 response redirects the client to a plaintext http:// URL. Browsers that ship the HSTS preload list are not affected, because the .dev top-level domain is preloaded; clients that do not enforce HSTS, such as command-line HTTP clients and scripts that follow redirects, are affected.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":17,"depthScoreParts":{"impact":17.1,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}