ELSA-2026-5581

ELSA-2026-5581 - nginx:1.24 security update

Type:SECURITY
Impact:MODERATE
Release Date:2026-03-24

Description


[1.24.0-2.0.1]
- Remove Red Hat references [Orabug: 29498217]

[1:1.24.0-2]
- Resolves: RHEL-146517 - nginx:1.24/nginx: NGINX: Data injection via
man-in-the-middle attack on TLS proxied connections (CVE-2026-1642)

[1:1.24.0-1]
- Resolves: RHEL-14714 - add nginx:1.24 to RHEL 8.10

[1:1.22.1-2]
- Resolves: RHEL-12728 - nginx:1.22/nginx: HTTP/2: Multiple HTTP/2 enabled web
servers are vulnerable to a DDoS attack (Rapid Reset Attack)(CVE-2023-44487)

[1:1.22.1-1]
- Resolves: #2112345 - nginx:1.22 for RHEL 8
- add stream_geoip_module and stream_realip_module
- remove obsolete --with-ipv6

[1:1.20.1-1]
- rebase to 1.20.1 (addressing CVE-2021-23017)

[1:1.20.0-4]
- add delaycompress to logrotate config (#2015243)

[1:1.20.0-3]
- Add -mod-devel subpackage for building external nginx modules (Neal Gompa)
Resolves: #1991787

[1:1.20.0-2]
- Resolves: #1991796 - build nginx with --with-compat

[1:1.20.0-1]
- new version 1.20.0
- Resolves: #1945671 - RFE: add nginx:1.20 module stream


Related CVEs


CVE-2026-1642

Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle Linux 8 (aarch64) nginx-1.24.0-2.0.1.module+el8.10.0+90849+dcad285b.src.rpm896f26a1237928daaea46fed0c9b6b24b9fbbabb1aa7de8d87f56a5777bb9f6d-ol8_aarch64_appstream
nginx-1.24.0-2.0.1.module+el8.10.0+90849+dcad285b.aarch64.rpm8852a4078a15df3f0e4b17825b3e639edea5535c65a446f4b461748654d62477-ol8_aarch64_appstream
nginx-all-modules-1.24.0-2.0.1.module+el8.10.0+90849+dcad285b.noarch.rpm2a8452284ad246563968d8d8d4fc1b0ac06b766c059792751c0b810c626a88e7-ol8_aarch64_appstream
nginx-filesystem-1.24.0-2.0.1.module+el8.10.0+90849+dcad285b.noarch.rpmebd6608c5cafffb7faa91efe4b340813e0d6eadfcb1a3c2f161d510d952fbf74-ol8_aarch64_appstream
nginx-mod-devel-1.24.0-2.0.1.module+el8.10.0+90849+dcad285b.aarch64.rpmf7c02fc81bdd01978750cee8f2eabd76b22ccf175df1f236da7c721396738d21-ol8_aarch64_appstream
nginx-mod-http-image-filter-1.24.0-2.0.1.module+el8.10.0+90849+dcad285b.aarch64.rpm9db5926ecbff05cb2cb52dca6b1965971e8673a61c15429fa29ebc24e46ced76-ol8_aarch64_appstream
nginx-mod-http-perl-1.24.0-2.0.1.module+el8.10.0+90849+dcad285b.aarch64.rpme81a57a629bc76402ce18e87aace9aad756d0b6848ce0ddc608058b84b9f5666-ol8_aarch64_appstream
nginx-mod-http-xslt-filter-1.24.0-2.0.1.module+el8.10.0+90849+dcad285b.aarch64.rpm7223102c3819bbd1c9f7183a2e58def2b58683fd02bc303b06bef10fdfa0402a-ol8_aarch64_appstream
nginx-mod-mail-1.24.0-2.0.1.module+el8.10.0+90849+dcad285b.aarch64.rpm143ef5065be5f5c96f07d1f4382b9d33135b48c7346938ddc40b303dd6321fcc-ol8_aarch64_appstream
nginx-mod-stream-1.24.0-2.0.1.module+el8.10.0+90849+dcad285b.aarch64.rpm345824c077e839b8b3a2e1e748a0ab68d7c45adad2a447567df599833b21b0c7-ol8_aarch64_appstream
Oracle Linux 8 (x86_64) nginx-1.24.0-2.0.1.module+el8.10.0+90849+dcad285b.src.rpm896f26a1237928daaea46fed0c9b6b24b9fbbabb1aa7de8d87f56a5777bb9f6d-ol8_x86_64_appstream
nginx-1.24.0-2.0.1.module+el8.10.0+90849+dcad285b.x86_64.rpm64bc184874db7332d62a12ed0cc0f8707f157cfc7d60eae4d75d9c7c82077703-ol8_x86_64_appstream
nginx-all-modules-1.24.0-2.0.1.module+el8.10.0+90849+dcad285b.noarch.rpm2a8452284ad246563968d8d8d4fc1b0ac06b766c059792751c0b810c626a88e7-ol8_x86_64_appstream
nginx-filesystem-1.24.0-2.0.1.module+el8.10.0+90849+dcad285b.noarch.rpmebd6608c5cafffb7faa91efe4b340813e0d6eadfcb1a3c2f161d510d952fbf74-ol8_x86_64_appstream
nginx-mod-devel-1.24.0-2.0.1.module+el8.10.0+90849+dcad285b.x86_64.rpm40af272d68fb55e259804e3e0b35e0ac09a5c3dde5060dfe99d2165dbe638032-ol8_x86_64_appstream
nginx-mod-http-image-filter-1.24.0-2.0.1.module+el8.10.0+90849+dcad285b.x86_64.rpmeb724357ad4f4c96044cd02ab682e1923c1987809e8a17a39268d3afec76ffb5-ol8_x86_64_appstream
nginx-mod-http-perl-1.24.0-2.0.1.module+el8.10.0+90849+dcad285b.x86_64.rpmddae19de49389801410946b16bd8c1a1c5407fa66596d04b5d48179e7cae1519-ol8_x86_64_appstream
nginx-mod-http-xslt-filter-1.24.0-2.0.1.module+el8.10.0+90849+dcad285b.x86_64.rpm74496d2481ea99b3e56e99533d27b209a82dfce120b5c8b6a9b4b95d8cebeca7-ol8_x86_64_appstream
nginx-mod-mail-1.24.0-2.0.1.module+el8.10.0+90849+dcad285b.x86_64.rpma11a20635fcddb1a31a53089c5d5f9c32147fa00d531b104a95ac8fa489c9ed2-ol8_x86_64_appstream
nginx-mod-stream-1.24.0-2.0.1.module+el8.10.0+90849+dcad285b.x86_64.rpmfa7d234b0f3b42a1390364a21b4bff6b799ba74680f2ce40a3d5eeac295ab446-ol8_x86_64_appstream



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete