"nginx":"1.26" nginx-1.26.3-9.module+el9+1197+d54167de.4
エラータID: AXSA:2026-1869:01
nginx is a web and proxy server supporting HTTP and other protocols, with a focus on high concurrency, performance, and low memory usage.
Security Fix(es):
* nginx: NGINX: Arbitrary code execution via crafted HTTP requests (CVE-2026-42533)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2026-42533
A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the map's regex capture variables before referencing the map output variable. Alternatively, the same result could be achieved by using a non-cacheable variable in a string expression under certain conditions. An unauthenticated attacker along with conditions beyond their control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Impact: This vulnerability may allow remote attackers to cause a denial-of-service (DoS) on the NGINX system or to possibly trigger a code execution. There is no control plane exposure; this is a data plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Modularity name: "nginx"
Stream name: "1.26"
Update packages.
A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the map's regex capture variables before referencing the map output variable. Alternatively, the same result could be achieved by using a non-cacheable variable in a string expression under certain conditions. An unauthenticated attacker along with conditions beyond their control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Impact: This vulnerability may allow remote attackers to cause a denial-of-service (DoS) on the NGINX system or to possibly trigger a code execution. There is no control plane exposure; this is a data plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
N/A
SRPMS
- nginx-1.26.3-9.module+el9+1197+d54167de.4.src.rpm
MD5: 219c7514f971e5de483b6f299b460a52
SHA-256: c2e99f7cc1aadcc5d969397e6b087f06444c7f3f7be3650adef10be0e039668f
Size: 1.30 MB
Asianux Server 9 for x86_64
- nginx-1.26.3-9.module+el9+1197+d54167de.4.x86_64.rpm
MD5: 75ab33632969b11f9be32fc858e8f185
SHA-256: 8ed74e977cb0529266c57cc60490261963e20d76f1d397aed0a2529cdfe64207
Size: 36.02 kB - nginx-all-modules-1.26.3-9.module+el9+1197+d54167de.4.noarch.rpm
MD5: 3359faf48a95f43d94cb38d63ccfb8b6
SHA-256: c3aa1be23710511a13510e77770837dc62ff2622d7b26afe720ec0b9e9a5d52d
Size: 8.59 kB - nginx-core-1.26.3-9.module+el9+1197+d54167de.4.x86_64.rpm
MD5: f98d82fce0f258ae51ec91a2830c5a15
SHA-256: 7d1f09a794aadbaca945dcfaf8c253d3e057c8a006ec540fedf3bf5a0a6b27fd
Size: 669.71 kB - nginx-debugsource-1.26.3-9.module+el9+1197+d54167de.4.x86_64.rpm
MD5: ab4bc9f0df673ab6e02b0f52945b143a
SHA-256: 7bb896a39de071ad5b72e5dbdb1a5460aed90811c7f956a1c836ae4678baebc8
Size: 703.96 kB - nginx-filesystem-1.26.3-9.module+el9+1197+d54167de.4.noarch.rpm
MD5: 68d2a650e5152cd6045735f54cd62662
SHA-256: bb1189e18d98c0fdb8aa0bfb9a6958d8fabeed0841c69b8828aaabbd984e812a
Size: 10.09 kB - nginx-mod-devel-1.26.3-9.module+el9+1197+d54167de.4.x86_64.rpm
MD5: 65d2956304c32fee670b06eae9763867
SHA-256: 9e6d46bc899742321f4a8676c38237ca344ee2c7b7a5fe3b6c2b81ba9aa90758
Size: 0.97 MB - nginx-mod-http-image-filter-1.26.3-9.module+el9+1197+d54167de.4.x86_64.rpm
MD5: 469b5886feda0e6f1e88473803f964dd
SHA-256: 2e66abf945527970b34d2f5fff514b67e20022b6f133417e996a6292d877f900
Size: 20.22 kB - nginx-mod-http-perl-1.26.3-9.module+el9+1197+d54167de.4.x86_64.rpm
MD5: 1a59e6ebba67120564d2006b28dacb87
SHA-256: 7342c809d8351ff61455d35e3944f64f2e6c86b5224a147256b76281bfcbd563
Size: 31.56 kB - nginx-mod-http-xslt-filter-1.26.3-9.module+el9+1197+d54167de.4.x86_64.rpm
MD5: 1329e8c7f1435950580ab95d9a493e53
SHA-256: 29e4f79ccc3b7bfa7d93d7cc3d37f8eb6b8ca26a75860cd147fe90c3bb2800a4
Size: 19.01 kB - nginx-mod-mail-1.26.3-9.module+el9+1197+d54167de.4.x86_64.rpm
MD5: a7773c080ec40837b979bfaed885ec67
SHA-256: 583895ff4ad551f1e687d4631e3c59d8db2d0f154c978c67e1380fcf1874f46c
Size: 53.63 kB - nginx-mod-stream-1.26.3-9.module+el9+1197+d54167de.4.x86_64.rpm
MD5: 18db1af8a4d443d2c38dc0123e5bf019
SHA-256: ad5f2d587e1b91548f09df650cad53791928449055e711c4e58315b50dc1ace9
Size: 86.10 kB