"nginx":"1.24" nginx-1.24.0-7.module+el9+1189+6ef24322.4.ML.1
エラータID: AXSA:2026-1718:01
nginx is a web and proxy server supporting HTTP and other protocols, with a focus on high concurrency, performance, and low memory usage.
Security Fix(es):
* nginx: NGINX: Heap buffer over-read allows memory modification or denial of service (CVE-2026-56434)
* nginx: NGINX: Memory disclosure and denial of service in ngx_http_slice_module (CVE-2026-60005)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2026-56434
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssi_module module. This vulnerability may exist when the Server-Side Includes (SSI), proxy_pass, and proxy_buffering off directives are configured. With this configuration, an unauthenticated attacker with man-in-the-middle (MITM) ability to control responses from an upstream server may be able to cause a use-after-free in the NGINX worker process. This issue may lead to limited modification of memory or a restart of the NGINX worker process. Impact: This vulnerability may allow remote attackers to have limited control to modify memory contents or restart the NGINX worker process. There is no control plane exposure; this is a data plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CVE-2026-60005
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module. When the slice directive and unnamed regex captures are configured or when a background cache update happens, unauthenticated attackers can send requests that may cause uninitialized memory access in the NGINX worker process, leading to limited disclosure of memory or a restart. Impact: This vulnerability may allow remote, unauthenticated attackers to have limited control to disclose memory contents or restart the NGINX worker process. There is no control plane exposure; this is a data plane issue only. Note: The ngx_http_slice_module module is not enabled by default; it's enabled with the --with-http_slice_module configuration parameter. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Modularity name: "nginx"
Stream name: "1.24"
Update packages.
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssi_module module. This vulnerability may exist when the Server-Side Includes (SSI), proxy_pass, and proxy_buffering off directives are configured. With this configuration, an unauthenticated attacker with man-in-the-middle (MITM) ability to control responses from an upstream server may be able to cause a use-after-free in the NGINX worker process. This issue may lead to limited modification of memory or a restart of the NGINX worker process. Impact: This vulnerability may allow remote attackers to have limited control to modify memory contents or restart the NGINX worker process. There is no control plane exposure; this is a data plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module. When the slice directive and unnamed regex captures are configured or when a background cache update happens, unauthenticated attackers can send requests that may cause uninitialized memory access in the NGINX worker process, leading to limited disclosure of memory or a restart. Impact: This vulnerability may allow remote, unauthenticated attackers to have limited control to disclose memory contents or restart the NGINX worker process. There is no control plane exposure; this is a data plane issue only. Note: The ngx_http_slice_module module is not enabled by default; it's enabled with the --with-http_slice_module configuration parameter. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
N/A
SRPMS
- nginx-1.24.0-7.module+el9+1189+6ef24322.4.ML.1.src.rpm
MD5: 508f04008bbf2cbb7073d649eb3d8fd8
SHA-256: 22076d32c4df3a48a77fe5a5c0cc84c1eb1a7d98eb440f103551d2819ea9b50a
Size: 1.14 MB
Asianux Server 9 for x86_64
- nginx-1.24.0-7.module+el9+1189+6ef24322.4.ML.1.x86_64.rpm
MD5: 4b5f0a3aa5883251d557f3f0cf651d9d
SHA-256: 8b8bb8ea944b36c723447a18b4ee3d07628d8d4e10f3858a3d3ffb3b8fd62235
Size: 37.28 kB - nginx-all-modules-1.24.0-7.module+el9+1189+6ef24322.4.ML.1.noarch.rpm
MD5: 9b886b3c3ca0bb6a03bac68ad461ca1a
SHA-256: d93964dd278b042b968b6ef3dd2d62ede0fe9a2a0662a3d8503298173f2110b0
Size: 8.75 kB - nginx-core-1.24.0-7.module+el9+1189+6ef24322.4.ML.1.x86_64.rpm
MD5: 52387a71d363f42ce804a63d6a2e84c8
SHA-256: eca46da857590641a57f8d5abacf0c8b0c512af4ad29fb9c1124cec2892e4a6a
Size: 584.84 kB - nginx-debugsource-1.24.0-7.module+el9+1189+6ef24322.4.ML.1.x86_64.rpm
MD5: e223597a51d017f9f7f97e267c9c0ee9
SHA-256: a9577828247e4483c13e2c2f4b9d8a66c2d08fe8c40bf084a5318151befee9c7
Size: 618.66 kB - nginx-filesystem-1.24.0-7.module+el9+1189+6ef24322.4.ML.1.noarch.rpm
MD5: 7ceef474f7fda3c8e6f0dc594778491f
SHA-256: 74fa447c021b326835eefb1efc5658200c77c5d9f530904cafe2d2d88ebed2cf
Size: 9.70 kB - nginx-mod-devel-1.24.0-7.module+el9+1189+6ef24322.4.ML.1.x86_64.rpm
MD5: 7bbeefbc4b2ef69482779ce52d6768e2
SHA-256: 61f5295a026ccf2d5273313edf03c274b215597a0457b87e350f68223324ec61
Size: 884.25 kB - nginx-mod-http-image-filter-1.24.0-7.module+el9+1189+6ef24322.4.ML.1.x86_64.rpm
MD5: c61aa05960c6d95a7786ea58223ae80a
SHA-256: 2bf7a4e7ace8e2280162068668271b39b297b65547dbf59bfb11370780b61157
Size: 20.36 kB - nginx-mod-http-perl-1.24.0-7.module+el9+1189+6ef24322.4.ML.1.x86_64.rpm
MD5: e034985bdc1b79e6d5a11e0fef37f111
SHA-256: 8ac3567594689f41b463163bd7b2002a82319c7d08417ac723c7f79070d5c091
Size: 31.72 kB - nginx-mod-http-xslt-filter-1.24.0-7.module+el9+1189+6ef24322.4.ML.1.x86_64.rpm
MD5: 9383f3131df4181f2e4394f50b5959e4
SHA-256: ba5cf5ccb9f0f4ef5550a8762c4a0fd136c185420021cfa9ad34b4b3a89fdabe
Size: 19.11 kB - nginx-mod-mail-1.24.0-7.module+el9+1189+6ef24322.4.ML.1.x86_64.rpm
MD5: a4f62fcee501d048b8d47895845e026f
SHA-256: c5ef9aa199d99ef3bd392a3b5a994ea56f4893f10b88dec5a9857fac3a797109
Size: 53.97 kB - nginx-mod-stream-1.24.0-7.module+el9+1189+6ef24322.4.ML.1.x86_64.rpm
MD5: f00de6c57a31842de21a7b0d43bd0af1
SHA-256: 996a02579da8d9ab3b26431d0f2ec6f346b04780a9f7d6ed0541cd3b69493993
Size: 80.64 kB