Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.1
nginx 1.26 Security Update Exposes Server to Malicious Access
RHSA-2026:17753
Summary
A security update is available for nginx 1.26 to fix a vulnerability that could allow an attacker to access the server without a valid login. This affects all systems running nginx 1.26. We recommend updating to the latest version to ensure the security of your server.
What to do
- Update redhat nginx to version 2:1.26.3-1.module+el9.6.0+24296+87cb744c.3.
- Update redhat nginx-all-modules to version 2:1.26.3-1.module+el9.6.0+24296+87cb744c.3.
- Update redhat nginx-core to version 2:1.26.3-1.module+el9.6.0+24296+87cb744c.3.
- Update redhat nginx-core-debuginfo to version 2:1.26.3-1.module+el9.6.0+24296+87cb744c.3.
- Update redhat nginx-debuginfo to version 2:1.26.3-1.module+el9.6.0+24296+87cb744c.3.
- Update redhat nginx-debugsource to version 2:1.26.3-1.module+el9.6.0+24296+87cb744c.3.
- Update redhat nginx-filesystem to version 2:1.26.3-1.module+el9.6.0+24296+87cb744c.3.
- Update redhat nginx-mod-devel to version 2:1.26.3-1.module+el9.6.0+24296+87cb744c.3.
- Update redhat nginx-mod-http-image-filter to version 2:1.26.3-1.module+el9.6.0+24296+87cb744c.3.
- Update redhat nginx-mod-http-image-filter-debuginfo to version 2:1.26.3-1.module+el9.6.0+24296+87cb744c.3.
- Update redhat nginx-mod-http-perl to version 2:1.26.3-1.module+el9.6.0+24296+87cb744c.3.
- Update redhat nginx-mod-http-perl-debuginfo to version 2:1.26.3-1.module+el9.6.0+24296+87cb744c.3.
- Update redhat nginx-mod-http-xslt-filter to version 2:1.26.3-1.module+el9.6.0+24296+87cb744c.3.
- Update redhat nginx-mod-http-xslt-filter-debuginfo to version 2:1.26.3-1.module+el9.6.0+24296+87cb744c.3.
- Update redhat nginx-mod-mail to version 2:1.26.3-1.module+el9.6.0+24296+87cb744c.3.
- Update redhat nginx-mod-mail-debuginfo to version 2:1.26.3-1.module+el9.6.0+24296+87cb744c.3.
- Update redhat nginx-mod-stream to version 2:1.26.3-1.module+el9.6.0+24296+87cb744c.3.
- Update redhat nginx-mod-stream-debuginfo to version 2:1.26.3-1.module+el9.6.0+24296+87cb744c.3.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| Red Hat:rhel_eus:9.6::appstream | redhat | nginx |
< 2:1.26.3-1.module+el9.6.0+24296+87cb744c.3 Fix: upgrade to 2:1.26.3-1.module+el9.6.0+24296+87cb744c.3
|
| Red Hat:rhel_eus:9.6::appstream | redhat | nginx-all-modules |
< 2:1.26.3-1.module+el9.6.0+24296+87cb744c.3 Fix: upgrade to 2:1.26.3-1.module+el9.6.0+24296+87cb744c.3
|
| Red Hat:rhel_eus:9.6::appstream | redhat | nginx-core |
< 2:1.26.3-1.module+el9.6.0+24296+87cb744c.3 Fix: upgrade to 2:1.26.3-1.module+el9.6.0+24296+87cb744c.3
|
| Red Hat:rhel_eus:9.6::appstream | redhat | nginx-core-debuginfo |
< 2:1.26.3-1.module+el9.6.0+24296+87cb744c.3 Fix: upgrade to 2:1.26.3-1.module+el9.6.0+24296+87cb744c.3
|
| Red Hat:rhel_eus:9.6::appstream | redhat | nginx-debuginfo |
< 2:1.26.3-1.module+el9.6.0+24296+87cb744c.3 Fix: upgrade to 2:1.26.3-1.module+el9.6.0+24296+87cb744c.3
|
| Red Hat:rhel_eus:9.6::appstream | redhat | nginx-debugsource |
< 2:1.26.3-1.module+el9.6.0+24296+87cb744c.3 Fix: upgrade to 2:1.26.3-1.module+el9.6.0+24296+87cb744c.3
|
| Red Hat:rhel_eus:9.6::appstream | redhat | nginx-filesystem |
< 2:1.26.3-1.module+el9.6.0+24296+87cb744c.3 Fix: upgrade to 2:1.26.3-1.module+el9.6.0+24296+87cb744c.3
|
| Red Hat:rhel_eus:9.6::appstream | redhat | nginx-mod-devel |
< 2:1.26.3-1.module+el9.6.0+24296+87cb744c.3 Fix: upgrade to 2:1.26.3-1.module+el9.6.0+24296+87cb744c.3
|
| Red Hat:rhel_eus:9.6::appstream | redhat | nginx-mod-http-image-filter |
< 2:1.26.3-1.module+el9.6.0+24296+87cb744c.3 Fix: upgrade to 2:1.26.3-1.module+el9.6.0+24296+87cb744c.3
|
| Red Hat:rhel_eus:9.6::appstream | redhat | nginx-mod-http-image-filter-debuginfo |
< 2:1.26.3-1.module+el9.6.0+24296+87cb744c.3 Fix: upgrade to 2:1.26.3-1.module+el9.6.0+24296+87cb744c.3
|
| Red Hat:rhel_eus:9.6::appstream | redhat | nginx-mod-http-perl |
< 2:1.26.3-1.module+el9.6.0+24296+87cb744c.3 Fix: upgrade to 2:1.26.3-1.module+el9.6.0+24296+87cb744c.3
|
| Red Hat:rhel_eus:9.6::appstream | redhat | nginx-mod-http-perl-debuginfo |
< 2:1.26.3-1.module+el9.6.0+24296+87cb744c.3 Fix: upgrade to 2:1.26.3-1.module+el9.6.0+24296+87cb744c.3
|
| Red Hat:rhel_eus:9.6::appstream | redhat | nginx-mod-http-xslt-filter |
< 2:1.26.3-1.module+el9.6.0+24296+87cb744c.3 Fix: upgrade to 2:1.26.3-1.module+el9.6.0+24296+87cb744c.3
|
| Red Hat:rhel_eus:9.6::appstream | redhat | nginx-mod-http-xslt-filter-debuginfo |
< 2:1.26.3-1.module+el9.6.0+24296+87cb744c.3 Fix: upgrade to 2:1.26.3-1.module+el9.6.0+24296+87cb744c.3
|
| Red Hat:rhel_eus:9.6::appstream | redhat | nginx-mod-mail |
< 2:1.26.3-1.module+el9.6.0+24296+87cb744c.3 Fix: upgrade to 2:1.26.3-1.module+el9.6.0+24296+87cb744c.3
|
| Red Hat:rhel_eus:9.6::appstream | redhat | nginx-mod-mail-debuginfo |
< 2:1.26.3-1.module+el9.6.0+24296+87cb744c.3 Fix: upgrade to 2:1.26.3-1.module+el9.6.0+24296+87cb744c.3
|
| Red Hat:rhel_eus:9.6::appstream | redhat | nginx-mod-stream |
< 2:1.26.3-1.module+el9.6.0+24296+87cb744c.3 Fix: upgrade to 2:1.26.3-1.module+el9.6.0+24296+87cb744c.3
|
| Red Hat:rhel_eus:9.6::appstream | redhat | nginx-mod-stream-debuginfo |
< 2:1.26.3-1.module+el9.6.0+24296+87cb744c.3 Fix: upgrade to 2:1.26.3-1.module+el9.6.0+24296+87cb744c.3
|
Original title
Red Hat Security Advisory: nginx:1.26 security update
osv CVSS3.1
8.1
- https://access.redhat.com/errata/RHSA-2026:17753 Vendor Advisory
- https://access.redhat.com/security/updates/classification/#critical Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2477116 Third Party Advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_17753.... Vendor Advisory
- https://access.redhat.com/security/cve/CVE-2026-42945 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-42945 Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-42945 Vendor Advisory
- https://depthfirst.com/nginx-rift Third Party Advisory
- https://my.f5.com/manage/s/article/K000161019 Third Party Advisory
Published: 16 May 2026 · Updated: 21 May 2026 · First seen: 21 May 2026