"nginx":"1.26" nginx-1.26.3-9.module+el9+1170+47214373.1
エラータID: AXSA:2026-1412:01
nginx is a web and proxy server supporting HTTP and other protocols, with a focus on high concurrency, performance, and low memory usage.
Security Fix(es):
* nginx: ngx_http_rewrite_module: code execution and denial of service (CVE-2026-9256)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2026-9256
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite directive uses a regex pattern with distinct, overlapping Perl-Compatible Regular Expression (PCRE) captures (for example, ^/((.*))$) and a replacement string that references multiple such captures (for example, $1$2) in a redirect or arguments context. An unauthenticated attacker along with conditions beyond their control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Modularity name: "nginx"
Stream name: "1.26"
Update packages.
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite directive uses a regex pattern with distinct, overlapping Perl-Compatible Regular Expression (PCRE) captures (for example, ^/((.*))$) and a replacement string that references multiple such captures (for example, $1$2) in a redirect or arguments context. An unauthenticated attacker along with conditions beyond their control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
N/A
SRPMS
- nginx-1.26.3-9.module+el9+1170+47214373.1.src.rpm
MD5: 08331ac5ef72446ca389997ea48e2c18
SHA-256: 1361c876442fa5ea02f1b86329bbe231083a4947dd73968341588f3085d0729a
Size: 1.28 MB
Asianux Server 9 for x86_64
- nginx-1.26.3-9.module+el9+1170+47214373.1.x86_64.rpm
MD5: d427ea3d99be345f8cd23c3f5ff56832
SHA-256: 48958d584af490d58e91b0f27101d4a12007f53207bb18f26dcfee409ab23b9a
Size: 35.70 kB - nginx-all-modules-1.26.3-9.module+el9+1170+47214373.1.noarch.rpm
MD5: 4db84767a14d8f093fb0b5b80683c68e
SHA-256: 9885ad38cb6f824ccd729acff2c99b1f1a9ddbfc07aa120f8b376bd961c64979
Size: 8.27 kB - nginx-core-1.26.3-9.module+el9+1170+47214373.1.x86_64.rpm
MD5: 9d518ea67c89d9f51bd4ce7d2b9c9779
SHA-256: e95d764740732f697932882902109cd11414d623d4b0069aada9e46bcf96e56f
Size: 667.15 kB - nginx-debugsource-1.26.3-9.module+el9+1170+47214373.1.x86_64.rpm
MD5: 10c10128fdb5a80ba391e03da4b2ba5d
SHA-256: 61abef3896420f0e022505a9e9ca3b90eb09ff8334141b9a0ee38a836d3f4eee
Size: 701.59 kB - nginx-filesystem-1.26.3-9.module+el9+1170+47214373.1.noarch.rpm
MD5: a1bffccfbbb14caeee00bc46352c30e5
SHA-256: 00a379aaf4e4ae684ca057de24a2b797b8ea2e661363b0e86dc1a03668cf96b4
Size: 9.77 kB - nginx-mod-devel-1.26.3-9.module+el9+1170+47214373.1.x86_64.rpm
MD5: fc182efe2a5f593b4ab6935e2c51fad9
SHA-256: 6d5c07029c3aa2e0a16c8de21fb1369707cad16d8b8ecd7f6ce36b3dd9ceec8c
Size: 0.96 MB - nginx-mod-http-image-filter-1.26.3-9.module+el9+1170+47214373.1.x86_64.rpm
MD5: ecf4a3350b2355a0525d113a0e8999a4
SHA-256: 0596cd3921da6886c2b2dbf372db5d103acf65692a5b19b42cfaffa51bf37d4d
Size: 19.91 kB - nginx-mod-http-perl-1.26.3-9.module+el9+1170+47214373.1.x86_64.rpm
MD5: 1467b0eb664207004b14c4fbeda3ae2b
SHA-256: d7ff3d9500958b2d93885b4702e09d4c80635e5c8a4ff87c830ef57826ba8fa5
Size: 31.24 kB - nginx-mod-http-xslt-filter-1.26.3-9.module+el9+1170+47214373.1.x86_64.rpm
MD5: 61333d14681aa81a33bfb64bd6a6d729
SHA-256: df059b7f30e64e01c2ac2ce91e5fbf7611514f0f67648e3322f1bbb54fa80d11
Size: 18.69 kB - nginx-mod-mail-1.26.3-9.module+el9+1170+47214373.1.x86_64.rpm
MD5: 349cfd61afe670a7077f4ba211f1028f
SHA-256: 720476ed8db713dfeb00b48e4a1cc618df398c54d4919884895aacfbfd39d799
Size: 53.31 kB - nginx-mod-stream-1.26.3-9.module+el9+1170+47214373.1.x86_64.rpm
MD5: 47abbd2c862ef951c0e041d52be32f08
SHA-256: 3a36877aba3101b7ed9547dfef1b75469710a30f2aba405c2ac60718252e5923
Size: 85.12 kB