Security News

Cybersecurity news aggregator

🔄
HIGH Updates Red Hat Errata

RHSA-2026:36639: Important: nginx:1.26 security, bug fix, and enhancement update

A heap-based buffer overflow vulnerability (CVE-2026-42055, CVSS 8.1 HIGH) in nginx allows arbitrary code execution or denial of service via crafted HTTP/2 headers. The vulnerability affects multiple F5 products, including nginx App Protect WAF versions 4.10.0 through 4.16.0 and 5.2.0 through 5.8.0, as well as nginx Gateway Fabric versions 1.3.0 through 1.6.2. Remediation requires upgrading to fixed versions, such as nginx App Protect WAF 5.5.1 or nginx Gateway Fabric 1.30.3, as specified in the NVD data.
Read Full Article →

Red Hat Product Errata RHSA-2026:36639 - Security Advisory Issued: 2026-07-08 Updated: 2026-07-08 RHSA-2026:36639 - Security Advisory Overview Updated Packages Synopsis Important: nginx:1.26 security, bug fix, and enhancement update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for the nginx:1.26 module is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description nginx is a web and proxy server supporting HTTP and other protocols, with a focus on high concurrency, performance, and low memory usage. Security Fix(es): nginx: NGINX: Arbitrary code execution or Denial of Service via heap-based buffer overflow with crafted HTTP/2 headers (CVE-2026-42055) Bug Fix(es) and Enhancement(s): nginx:1.26/nginx: "HTTP/2 bomb" nginx fix breaks module ABI causing crashes [rhel-9.8.z] (JIRA:RHEL-191774) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 9 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.8 x86_64 Red Hat Enterprise Linux for IBM z Systems 9 s390x Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.8 s390x Red Hat Enterprise Linux for Power, little endian 9 ppc64le Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.8 ppc64le Red Hat Enterprise Linux for ARM 64 9 aarch64 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.8 aarch64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.8 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.8 x86_64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.8 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.8 s390x Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.8 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.8 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.8 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.8 s390x Fixes BZ - 2489866 - CVE-2026-42055 nginx: NGINX: Arbitrary code execution or Denial of Service via heap-based buffer overflow with crafted HTTP/2 headers CVEs CVE-2026-42055 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 9 SRPM nginx-1.26.3-9.module+el9.8.0+24501+a1e882cd.2.src.rpm SHA-256: 8d212a68ade8a03b2ed708ef6fe3f7187113adbcc6129ad17bc24b50d342e852 x86_64 nginx-all-modules-1.26.3-9.module+el9.8.0+24501+a1e882cd.2.noarch.rpm SHA-256: 6e7cef1bb28ed4ba232812e9c32c47441067dd06ffbf6aa65a2f0952f8801e40 nginx-filesystem-1.26.3-9.module+el9.8.0+24501+a1e882cd.2.noarch.rpm SHA-256: 4d3576228145c86d19dcc901bc58ce2599a5fc7ded384ba126d3e7fb61e14d18 nginx-1.26.3-9.module+el9.8.0+24501+a1e882cd.2.x86_64.rpm SHA-256: 1dc6fa4874ef22f4c138b18f80ed281d11dbac1441012cb5277ef905bd24f92a nginx-all-modules-1.26.3-9.module+el9.8.0+24501+a1e882cd.2.noarch.rpm SHA-256: 6e7cef1bb28ed4ba232812e9c32c47441067dd06ffbf6aa65a2f0952f8801e40 nginx-core-1.26.3-9.module+el9.8.0+24501+a1e882cd.2.x86_64.rpm SHA-256: f24f901ebd7c51b4a1bbb2c60d375c9ccc8210becccddfa34838d04d8bd8dc68 nginx-core-debuginfo-1.26.3-9.module+el9.8.0+24501+a1e882cd.2.x86_64.rpm SHA-256: 5213b253acc2528370711fba8620205eb899df775ae0b5daa69e625372bf4000 nginx-debuginfo-1.26.3-9.module+el9.8.0+24501+a1e882cd.2.x86_64.rpm SHA-256: 4227cb0e81b8d38906453275ca83e12da836a5f5b5e3465c81457a3f532f4270 nginx-debugsource-1.26.3-9.module+el9.8.0+24501+a1e882cd.2.x86_64.rpm SHA-256: 86da30257c3b7a480aaf7b2bb7ea4b9ee38d7bd4f25c438bbe550d75d2240122 nginx-filesystem-1.26.3-9.module+el9.8.0+24501+a1e882cd.2.noarch.rpm SHA-256: 4d3576228145c86d19dcc901bc58ce2599a5fc7ded384ba126d3e7fb61e14d18 nginx-mod-devel-1.26.3-9.module+el9.8.0+24501+a1e882cd.2.x86_64.rpm SHA-256: ac3d211d54f0be0eda9d68b43e67b26064f0a675475cf923e535ed83091204d3 nginx-mod-http-image-filter-1.26.3-9.module+el9.8.0+24501+a1e882cd.2.x86_64.rpm SHA-256: 1289ff4e72ee3acb46c9fd254e98c24685531bda02a7fbe07887e47e3d5f18f6 nginx-mod-http-image-filter-debuginfo-1.26.3-9.module+el9.8.0+24501+a1e882cd.2.x86_64.rpm SHA-256: 38ab20ac1010ac580728b25af844ef47eb2d62e68b1f1efc626a523c6ae5ca48 nginx-mod-http-perl-1.26.3-9.module+el9.8.0+24501+a1e882cd.2.x86_64.rpm SHA-256: 6916630065e491b0e4ada555af2abc261e8bcbe6d3618ff702f3fe05c23b98af nginx-mod-http-perl-debuginfo-1.26.3-9.module+el9.8.0+24501+a1e882cd.2.x86_64.rpm SHA-256: 89187cf2be12aa12a88542b358b1a1e9f79fa51ecdf3ade8d3e597342c7c73e8 nginx-mod-http-xslt-filter-1.26.3-9.module+el9.8.0+24501+a1e882cd.2.x86_64.rpm SHA-256: 47d373f6fba85ef479d813dc59ecddc42ddd7120222018d28b77f7f0e424b4d3 nginx-mod-http-xslt-filter-debuginfo-1.26.3-9.module+el9.8.0+24501+a1e882cd.2.x86_64.rpm SHA-256: 188925812fd1ccbbc271e2dc77e599049acfc7efeb3e9cfcfb171ae1b2d5cbd8 nginx-mod-mail-1.26.3-9.module+el9.8.0+24501+a1e882cd.2.x86_64.rpm SHA-256: 314572b0a746dfade54c1f4e399a10807d5108b44e8bddc92200ee5e28fde9c3 nginx-mod-mail-debuginfo-1.26.3-9.module+el9.8.0+24501+a1e882cd.2.x86_64.rpm SHA-256: d36d5f48d76c2fbb6839bd06bb7d0218c8374860a8c28123e76c77b78a7d9e7f nginx-mod-stream-1.26.3-9.module+el9.8.0+24501+a1e882cd.2.x86_64.rpm SHA-256: c4e5a9bdbc9204feae3ef47c41b33c54433a069db86aff651ad26bda9a70c274 nginx-mod-stream-debuginfo-1.26.3-9.module+el9.8.0+24501+a1e882cd.2.x86_64.rpm SHA-256: 39c72956fdc6ed82a8363976b48feb9dd9c5fb2cae9b5553f114bd748afb127d nginx-all-modules-1.26.3-9.module+el9.8.0+24501+a1e882cd.2.noarch.rpm SHA-256: 6e7cef1bb28ed4ba232812e9c32c47441067dd06ffbf6aa65a2f0952f8801e40 nginx-filesystem-1.26.3-9.module+el9.8.0+24501+a1e882cd.2.noarch.rpm SHA-256: 4d3576228145c86d19dcc901bc58ce2599a5fc7ded384ba126d3e7fb61e14d18 nginx-all-modules-1.26.3-9.module+el9.8.0+24501+a1e882cd.2.noarch.rpm SHA-256: 6e7cef1bb28ed4ba232812e9c32c47441067dd06ffbf6aa65a2f0952f8801e40 nginx-filesystem-1.26.3-9.module+el9.8.0+24501+a1e882cd.2.noarch.rpm SHA-256: 4d3576228145c86d19dcc901bc58ce2599a5fc7ded384ba126d3e7fb61e14d18 Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.8 SRPM nginx-1.26.3-9.module+el9.8.0+24501+a1e882cd.2.src.rpm SHA-256: 8d212a68ade8a03b2ed708ef6fe3f7187113adbcc6129ad17bc24b50d342e852 x86_64 nginx-all-modules-1.26.3-9.module+el9.8.0+24501+a1e882cd.2.noarch.rpm SHA-256: 6e7cef1bb28ed4ba232812e9c32c47441067dd06ffbf6aa65a2f0952f8801e40 nginx-filesystem-1.26.3-9.module+el9.8.0+24501+a1e882cd.2.noarch.rpm SHA-256: 4d3576228145c86d19dcc901bc58ce2599a5fc7ded384ba126d3e7fb61e14d18 nginx-1.26.3-9.module+el9.8.0+24501+a1e882cd.2.x86_64.rpm SHA-256: 1dc6fa4874ef22f4c138b18f80ed281d11dbac1441012cb5277ef905bd24f92a nginx-all-modules-1.26.3-9.module+el9.8.0+24501+a1e882cd.2.noarch.rpm SHA-256: 6e7cef1bb28ed4ba232812e9c32c47441067dd06ffbf6aa65a2f0952f8801e40 nginx-core-1.26.3-9.module+el9.8.0+24501+a1e882cd.2.x86_64.rpm SHA-256: f24f901ebd7c51b4a1bbb2c60d375c9ccc8210becccddfa34838d04d8bd8dc68 nginx-core-debuginfo-1.26.3-9.module+el9.8.0+24501+a1e882cd.2.x86_64.rpm SHA-256: 5213b253acc2528370711fba8620205eb899df775ae0b5daa69e625372bf4000 nginx-debuginfo-1.26.3-9.module+el9.8.0+24501+a1e882cd.2.x86_64.rpm SHA-256: 4227cb0e81b8d38906453275ca83e12da836a5f5b5e3465c81457a3f532f4270 nginx-debugsource-1.26.3-9.module+el9.8.0+24501+a1e882cd.2.x86_64.rpm SHA-256: 86da30257c3b7a480aaf7b2bb7ea4b9ee38d7bd4f25c438bbe550d75d2240122 nginx-filesystem-1.26.3-9.module+el9.8.0+24501+a1e882cd.2.noarch.rpm SHA-256: 4d3576228145c86d19dcc901bc58ce2599a5fc7ded384ba126d3e7fb61e14d18 nginx-mod-devel-1.26.3-9.module+el9.8.0+24501+a1e882cd.2.x86_64.rpm SHA-256: ac3d211d54f0be0eda9d68b43e67b26064f0a675475cf923e535ed83091204d3 nginx-mod-http-image-filter-1.26.3-9.module+el9.8.0+24501+a1e882cd.2.x86_64.rpm SHA-256: 1289ff4e72ee3acb46c9fd254e98c24685531bda02a7fbe07887e47e3d5f18f6 nginx-mod-http-image-filter-debuginfo-1.26.3-9.module+el9.8.0+24501+a1e882cd.2.x86_64.rpm SHA-256: 38ab20ac1010ac580728b25af844ef47eb2d62e68b1f1efc626a523c6ae5ca48 nginx-mod-http-perl-1.26.3-9.module+el9.8.0+24501+a1e882cd.2.x86_64.rpm SHA-256: 6916630065e491b0e4ada555af2abc261e8bcbe6d3618ff702f3fe05c23b98af nginx-mod-http-perl-debuginfo-1.26.3-9.module+el9.8.0+24501+a1e882cd.2.x86_64.rpm SHA-256: 89187cf2be12aa12a88542b358b1a1e9f79fa51ecdf3ade8d3e597342c7c73e8 nginx-mod-http-xslt-filter-1.26.3-9.module+el9.8.0+24501+a1e882cd.2.x86_64.rpm SHA-256: 47d373f6fba85ef479d813dc59ecddc42ddd7120222018d28b77f7f0e424b4d3 nginx-mod-http-xslt-filter-debuginfo-1.26.3-9.module+el9.8.0+24501+a1e882cd.2.x86_64.rpm SHA-256: 188925812fd1ccbbc271e2dc77e599049acfc7efeb3e9cfcfb171ae1b2d5cbd8 nginx-mod-mail-1.26.3-9.module+el9.8.0+24501+a1e882cd.2.x86_64.rpm SHA-256: 314572b0a746dfade54c1f4e399a10807d5108b44e8bddc92200ee5e28fde9c3 nginx-mod-mail-debuginfo-1.26.3-9.module+el9.8.0+24501+a1e882cd.2.x86_64.rpm SHA-256: d36d5f48d76c2fbb6839bd06bb7d0218c8374860a8c28123e76c77b78a7d9e7f nginx-mod-stream-1.26.3-9.module+el9.8.0+24501+a1e882cd.2.x86_64.rpm SHA-256: c4e5a9bdbc9204feae3ef47c41b33c54433a069db86aff651ad26bda9a70c274 nginx-mod-stream-debuginfo-1.26.3-9.module+el9.8.0+24501+a1e882cd.2.x86_64.rpm SHA-256: 39c72956fdc6ed82a8363976b48feb9dd9c5fb2cae9b5553f114bd748afb127d nginx-all-modules-1.26.3-9.module+el9.8.0+24501+a1e882cd.2.noarch.rpm SHA-256: 6e7cef1bb28ed4ba232812e9c32c4

Share this article