ELSA-2026-67283-0

ELSA-2026-67283-0 - nginx:1.26 security update

Type:SECURITY
Impact:MODERATE
Release Date:2026-09-15

Description


[1.26.3-9.4.0.1]
- Require oracle-indexhtml

[2:1.26.3-14]
- Fixes CVE-2026-42533

[2:1.26.3-13]
- Fixes CVE-2026-56434 and CVE-2026-60005

[2:1.26.3-12]
- Resolves: RHEL-191774 - nginx: 'HTTP/2 bomb' nginx fix breaks module ABI
causing crashes

[2:1.26.3-11]
- nginx:1.26/nginx: HTTP/2: Remote Denial of Service via compression bomb
and Slowloris-style attack

[2:1.26.3-10]
- nginx: code execution and denial of service (CVE-2026-9256)

[2:1.26.3-9]
- Resolves: RHEL-176218 - nginx:1.26/nginx: NGINX: Arbitrary Code Execution
Vulnerability (CVE-2026-42945)

[2:1.26.3-8]
- CVE-2026-32647 nginx:1.26/nginx: NGINX: Denial of Service or Code
Execution via specially crafted MP4 files

[2:1.26.3-7]
- CVE-2026-27651 nginx:1.26/nginx: NGINX: Denial of Service via undisclosed
requests when ngx_mail_auth_http_module is enabled

[2:1.26.3-6]
- CVE-2026-27784 nginx:1.26/nginx: NGINX: Denial of Service due to memory
corruption via crafted MP4 file


Related CVEs


CVE-2026-42533

Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle Linux 9 (aarch64) nginx-1.26.3-9.0.1.module+el9.8.0+91031+6e548d4b.4.src.rpm7e837161357eac4533efdd29f027e493474c21127289fda335d006b46cd0abd3-ol9_aarch64_appstream
nginx-1.26.3-9.0.1.module+el9.8.0+91031+6e548d4b.4.aarch64.rpm12f322abb3b3a46df5815bac213bbefb0a86a5e09344a49f7000ffa79ed592d3-ol9_aarch64_appstream
nginx-all-modules-1.26.3-9.0.1.module+el9.8.0+91031+6e548d4b.4.noarch.rpm6bf226e3a567ae66a48bd69db11191adce0956333e87cbdb2222b25e5bd1ed47-ol9_aarch64_appstream
nginx-core-1.26.3-9.0.1.module+el9.8.0+91031+6e548d4b.4.aarch64.rpm88988b171362d023e8ad05854eab8a95065a4d50687c5b9c072b4316c14de561-ol9_aarch64_appstream
nginx-filesystem-1.26.3-9.0.1.module+el9.8.0+91031+6e548d4b.4.noarch.rpm4c6d564acfa04505694434fd84b3475cfdcfb6e310fc30663acb57ea97f895c5-ol9_aarch64_appstream
nginx-mod-devel-1.26.3-9.0.1.module+el9.8.0+91031+6e548d4b.4.aarch64.rpm8538e7a288a9b1d4e6a0f4035e2c6191869b54ebcdfd6f4a1839f263468418cd-ol9_aarch64_appstream
nginx-mod-http-image-filter-1.26.3-9.0.1.module+el9.8.0+91031+6e548d4b.4.aarch64.rpme2d924dfc024538965bbcaa72df35c41bc5c5d745e1116cef7229216ecbf5e03-ol9_aarch64_appstream
nginx-mod-http-perl-1.26.3-9.0.1.module+el9.8.0+91031+6e548d4b.4.aarch64.rpm2f1f96d65c1584243747d4b96d6f7dc23719d16ae2975f523b5a11c990f67b7f-ol9_aarch64_appstream
nginx-mod-http-xslt-filter-1.26.3-9.0.1.module+el9.8.0+91031+6e548d4b.4.aarch64.rpme178296e8568377a5a8e69e5ec3c74ed9d0bd99fbcea5eb8c133e9ba1b9d01fb-ol9_aarch64_appstream
nginx-mod-mail-1.26.3-9.0.1.module+el9.8.0+91031+6e548d4b.4.aarch64.rpm7f05e5c8fdf1542410f642a94b699ccbd703617b17a6f290363f97c64246183a-ol9_aarch64_appstream
nginx-mod-stream-1.26.3-9.0.1.module+el9.8.0+91031+6e548d4b.4.aarch64.rpm11838590dd7dfd316cbd6179f9fa480bf32f217766b46cfd9bb5b82fcb70cce7-ol9_aarch64_appstream
Oracle Linux 9 (x86_64) nginx-1.26.3-9.0.1.module+el9.8.0+91031+6e548d4b.4.src.rpm7e837161357eac4533efdd29f027e493474c21127289fda335d006b46cd0abd3-ol9_x86_64_appstream
nginx-1.26.3-9.0.1.module+el9.8.0+91031+6e548d4b.4.x86_64.rpmb60d8d71a9210dafd3bf117b6759b7d31e0d0f611bc35cfc82e48f86df70cbd6-ol9_x86_64_appstream
nginx-all-modules-1.26.3-9.0.1.module+el9.8.0+91031+6e548d4b.4.noarch.rpm6bf226e3a567ae66a48bd69db11191adce0956333e87cbdb2222b25e5bd1ed47-ol9_x86_64_appstream
nginx-core-1.26.3-9.0.1.module+el9.8.0+91031+6e548d4b.4.x86_64.rpm0f0015170f595e5230079d6aa07399109aef5bcd7c93162bbb1a6604f387724c-ol9_x86_64_appstream
nginx-filesystem-1.26.3-9.0.1.module+el9.8.0+91031+6e548d4b.4.noarch.rpm4c6d564acfa04505694434fd84b3475cfdcfb6e310fc30663acb57ea97f895c5-ol9_x86_64_appstream
nginx-mod-devel-1.26.3-9.0.1.module+el9.8.0+91031+6e548d4b.4.x86_64.rpma83c0a28b3fcca049366d2caf10e83efcdb5066f10c66a09434f88908bbf3296-ol9_x86_64_appstream
nginx-mod-http-image-filter-1.26.3-9.0.1.module+el9.8.0+91031+6e548d4b.4.x86_64.rpm31970aac01408c2f935a7060c24e313e236291026024c12626c8ddac876b2ec8-ol9_x86_64_appstream
nginx-mod-http-perl-1.26.3-9.0.1.module+el9.8.0+91031+6e548d4b.4.x86_64.rpm23a09385cbfa5af5766b21659af0d852a5d4e380d7766416fa800d02cc6edf75-ol9_x86_64_appstream
nginx-mod-http-xslt-filter-1.26.3-9.0.1.module+el9.8.0+91031+6e548d4b.4.x86_64.rpm03d151c2fb3341e65ccfe409a92a8013c6d829e01c555253180aa76e036ab6b0-ol9_x86_64_appstream
nginx-mod-mail-1.26.3-9.0.1.module+el9.8.0+91031+6e548d4b.4.x86_64.rpm1a8cc0813e1d13205677f986cf85a74ef4da996a7e1b7217429dd5c1c81b0d33-ol9_x86_64_appstream
nginx-mod-stream-1.26.3-9.0.1.module+el9.8.0+91031+6e548d4b.4.x86_64.rpmed6e2fd8763b47c4522112966c5d37562beb425f2fb09582a095009dc448af46-ol9_x86_64_appstream



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete