Dante Domain Manager (DDM) is not affected by nginx CVE-2026-1642
Some vulnerability scanners have reported a potential issue with Dante Domain Manager (DDM) as follows:
- A vulnerability exists in NGINX OSS and NGINX Plus when configured to proxy to upstream Transport Layer Security (TLS) servers. An attacker with a man-in-the-middle (MITM) position on the upstream server side–along with conditions beyond the attacker’s control–may be able to inject plain text data into the response from an upstream proxied server.
We can confirm that although Dante Domain Manager uses an affected version of nginx (as of DDM v1.8.3) it does not use it in the configuration described in CVE-2026-1642 and therefore does not present a vulnerability risk.