"nginx":"1.26" nginx-1.26.3-9.module+el9+1190+abc666e8.3

エラータID: AXSA:2026-1722:01

Release date: 
Tuesday, September 1, 2026 - 20:45
Subject: 
"nginx":"1.26" nginx-1.26.3-9.module+el9+1190+abc666e8.3
Affected Channels: 
MIRACLE LINUX 9 for x86_64
Severity: 
High
Description: 

nginx is a web and proxy server supporting HTTP and other protocols, with a focus on high concurrency, performance, and low memory usage.

Security Fix(es):

* nginx: NGINX: Heap buffer over-read allows memory modification or denial of service (CVE-2026-56434)
* nginx: NGINX: Memory disclosure and denial of service in ngx_http_slice_module (CVE-2026-60005)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2026-56434
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssi_module module. This vulnerability may exist when the Server-Side Includes (SSI), proxy_pass, and proxy_buffering off directives are configured. With this configuration, an unauthenticated attacker with man-in-the-middle (MITM) ability to control responses from an upstream server may be able to cause a use-after-free in the NGINX worker process. This issue may lead to limited modification of memory or a restart of the NGINX worker process. Impact: This vulnerability may allow remote attackers to have limited control to modify memory contents or restart the NGINX worker process. There is no control plane exposure; this is a data plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CVE-2026-60005
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module. When the slice directive and unnamed regex captures are configured or when a background cache update happens, unauthenticated attackers can send requests that may cause uninitialized memory access in the NGINX worker process, leading to limited disclosure of memory or a restart. Impact: This vulnerability may allow remote, unauthenticated attackers to have limited control to disclose memory contents or restart the NGINX worker process. There is no control plane exposure; this is a data plane issue only. Note: The ngx_http_slice_module module is not enabled by default; it's enabled with the --with-http_slice_module configuration parameter. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Modularity name: "nginx"
Stream name: "1.26"

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. nginx-1.26.3-9.module+el9+1190+abc666e8.3.src.rpm
    MD5: 9b6b724949c97acced413c5467e20a23
    SHA-256: 535882a6d6f736ff00db7f9cd8bcf80dbe617a397d5415e0c22e037777fa4817
    Size: 1.29 MB

Asianux Server 9 for x86_64
  1. nginx-1.26.3-9.module+el9+1190+abc666e8.3.x86_64.rpm
    MD5: 35e024f9295881161188e46d9ef9df65
    SHA-256: bcbba8212436ab3e124cb17816ef4bc209ca4dacab9e36bda65523f46ffe9857
    Size: 35.96 kB
  2. nginx-all-modules-1.26.3-9.module+el9+1190+abc666e8.3.noarch.rpm
    MD5: ef450e096115bcd5d76d507d56a762bb
    SHA-256: 0fa183e7db37e145ac388157b6c554feadc69b1062b528f77e9859da61949606
    Size: 8.52 kB
  3. nginx-core-1.26.3-9.module+el9+1190+abc666e8.3.x86_64.rpm
    MD5: a4b7be0be8e638b443ac35dbe226daf8
    SHA-256: 5b656b8052d405c01363aa88003d8ed11216113b5d0b386d1e5a5c0fa9f0dc76
    Size: 667.75 kB
  4. nginx-debugsource-1.26.3-9.module+el9+1190+abc666e8.3.x86_64.rpm
    MD5: 794b73f6973777752459f50abc6678d9
    SHA-256: 5e5a7b646be92f1253b7a8526c4bec48ce5e4518da56884973cae7343872f1b5
    Size: 703.04 kB
  5. nginx-filesystem-1.26.3-9.module+el9+1190+abc666e8.3.noarch.rpm
    MD5: ce6bc1968387a5b4d7119fb3914a18a3
    SHA-256: 578cffd131e604fd617547f98260df1907049044fcc558b956a45cf625e294a0
    Size: 10.01 kB
  6. nginx-mod-devel-1.26.3-9.module+el9+1190+abc666e8.3.x86_64.rpm
    MD5: 920c5d5ac43fe5ed2c82baf73d4285f2
    SHA-256: f7105f5977b130953b553eed8a5197ab6766ceb5de70f6bdf5eb06d1b5185e93
    Size: 0.96 MB
  7. nginx-mod-http-image-filter-1.26.3-9.module+el9+1190+abc666e8.3.x86_64.rpm
    MD5: acedffa5f1307640ebff161c8a963f8f
    SHA-256: fc85f8adcf8fa6f15c932be05dba9dfd9f1ff7ba3ca4776f1c9ca0b2d8ee37f8
    Size: 20.15 kB
  8. nginx-mod-http-perl-1.26.3-9.module+el9+1190+abc666e8.3.x86_64.rpm
    MD5: b2ef127c41ef21307fc7e639b61560e8
    SHA-256: 59dfa3ea3fa2ef4321863f1021266ce2d9e6bcc59f4e0fcf710eb77591047d68
    Size: 31.58 kB
  9. nginx-mod-http-xslt-filter-1.26.3-9.module+el9+1190+abc666e8.3.x86_64.rpm
    MD5: 8ba1d15442daab6b9b12b48af004411e
    SHA-256: d4118098849398ce108c6c220cf4733031731271d72ec4244133fa6e66bbe283
    Size: 18.92 kB
  10. nginx-mod-mail-1.26.3-9.module+el9+1190+abc666e8.3.x86_64.rpm
    MD5: 5d5727d35aa7f12e4f821e9dfa355ab4
    SHA-256: 7e2c5c27cc19bdc0f32ed4cbbd443343e1c33353fdec07b9d54a978e715cc019
    Size: 53.56 kB
  11. nginx-mod-stream-1.26.3-9.module+el9+1190+abc666e8.3.x86_64.rpm
    MD5: f7beb88cba2bde76ad60e5d86a899576
    SHA-256: 41fbc4c62ab4bfdd3c66733a9f1fd69a95f295e4147d84e86f065c7c9e820ac5
    Size: 85.39 kB