"nginx":"1.24" nginx-1.24.0-7.module+el9+1169+523796cb.2.ML.1
エラータID: AXSA:2026-1411:01
nginx is a web and proxy server supporting HTTP and other protocols, with a focus on high concurrency, performance, and low memory usage.
Security Fix(es):
* nginx: ngx_http_rewrite_module: code execution and denial of service (CVE-2026-9256)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2026-9256
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite directive uses a regex pattern with distinct, overlapping Perl-Compatible Regular Expression (PCRE) captures (for example, ^/((.*))$) and a replacement string that references multiple such captures (for example, $1$2) in a redirect or arguments context. An unauthenticated attacker along with conditions beyond their control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Modularity name: "nginx"
Stream name: "1.24"
Update packages.
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite directive uses a regex pattern with distinct, overlapping Perl-Compatible Regular Expression (PCRE) captures (for example, ^/((.*))$) and a replacement string that references multiple such captures (for example, $1$2) in a redirect or arguments context. An unauthenticated attacker along with conditions beyond their control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
N/A
SRPMS
- nginx-1.24.0-7.module+el9+1169+523796cb.2.ML.1.src.rpm
MD5: b03ad75c8112633ec4e3266f9d2e7534
SHA-256: 0f735f21b9f81cc0aededd7958859a32b829b6b16dc33444c3b9883f3d526e47
Size: 1.14 MB
Asianux Server 9 for x86_64
- nginx-1.24.0-7.module+el9+1169+523796cb.2.ML.1.x86_64.rpm
MD5: cfcb3f344fe8f4f3a9a391aee31f1412
SHA-256: 7df329178503e0f2d1abc636ede7536ad1b5624e65de771bb4b9ff3242cd32d5
Size: 36.64 kB - nginx-all-modules-1.24.0-7.module+el9+1169+523796cb.2.ML.1.noarch.rpm
MD5: 53577e17365803a279aca98b401c7e38
SHA-256: 859d5472c5401d3eb6e98866f87f25f9451efef7091e1140939b7ad0e8f48a4f
Size: 8.13 kB - nginx-core-1.24.0-7.module+el9+1169+523796cb.2.ML.1.x86_64.rpm
MD5: 0695cbc6e357ef32a31a15e83a02c564
SHA-256: 7555a7bd7f68383b0bbc88ab0265a1c6529df18110d9c89ff1da693bae4ad464
Size: 583.68 kB - nginx-debugsource-1.24.0-7.module+el9+1169+523796cb.2.ML.1.x86_64.rpm
MD5: 9fc34bade72ba5ab99e9d78c4ceff0f2
SHA-256: ed462b687b7db219fe91328a78fac70ba53181ccafb466286f6da2663d21e020
Size: 616.64 kB - nginx-filesystem-1.24.0-7.module+el9+1169+523796cb.2.ML.1.noarch.rpm
MD5: 6a671e9f7d8f8c330f536a0321cbd00b
SHA-256: 3fde5914f3c04a20a7f3f33aba438d62252bbbea1641dde167b9d0e5a2aa06cf
Size: 9.09 kB - nginx-mod-devel-1.24.0-7.module+el9+1169+523796cb.2.ML.1.x86_64.rpm
MD5: 7024da293281dbb028aa0408fa63adc3
SHA-256: 91be33e5d3b4b43ef6d86fe1332dbcf905da0da0cf851229f800ca534ca0b77d
Size: 882.65 kB - nginx-mod-http-image-filter-1.24.0-7.module+el9+1169+523796cb.2.ML.1.x86_64.rpm
MD5: baf22e891277878b2c08f26db622280e
SHA-256: 79886d3f030111feebe85f0714ce22263d5ae3eaf2b42b9f609a61c4f04c7493
Size: 19.75 kB - nginx-mod-http-perl-1.24.0-7.module+el9+1169+523796cb.2.ML.1.x86_64.rpm
MD5: 11c50a55745563c2010d3c646b40ffab
SHA-256: 2705a6178f252c4f9da1312184a2d025ad416db44d6d499e1eab5e5f23f1f3fa
Size: 31.12 kB - nginx-mod-http-xslt-filter-1.24.0-7.module+el9+1169+523796cb.2.ML.1.x86_64.rpm
MD5: e794bb6c7fccfba4928a4a3da7991eb8
SHA-256: 0fbc1bc61663be6ab5a0c4257224875374c2582933c6cb1a3d3f7cf640184d74
Size: 18.51 kB - nginx-mod-mail-1.24.0-7.module+el9+1169+523796cb.2.ML.1.x86_64.rpm
MD5: 04387c4884c2e3b0f17fb3ad154640fe
SHA-256: ded1b5f87afb8c1df6bf763a22598f56109c7ac719eec5fc6fa093c763d3a150
Size: 53.36 kB - nginx-mod-stream-1.24.0-7.module+el9+1169+523796cb.2.ML.1.x86_64.rpm
MD5: d83de5545ee9b78394566cbdcd74e970
SHA-256: 29c01af27f75197fee8e81d8f7c96afc08c6e0a53a13a4b3931e3df30c928327
Size: 80.04 kB