Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.1

nginx: Remote Code Execution via Specially Crafted HTTP Request

RHSA-2026:17791
Summary

A security update is available for nginx to fix a vulnerability that could allow an attacker to execute malicious code on your server. This affects servers running nginx, and you should update to the latest version to protect your system. Update your nginx installation as soon as possible to prevent potential attacks.

What to do
  • Update redhat nginx to version 1:1.20.1-10.el9_0.4.
  • Update redhat nginx-all-modules to version 1:1.20.1-10.el9_0.4.
  • Update redhat nginx-filesystem to version 1:1.20.1-10.el9_0.4.
  • Update redhat nginx-mod-http-image-filter to version 1:1.20.1-10.el9_0.4.
  • Update redhat nginx-mod-http-perl to version 1:1.20.1-10.el9_0.4.
  • Update redhat nginx-mod-http-xslt-filter to version 1:1.20.1-10.el9_0.4.
  • Update redhat nginx-mod-mail to version 1:1.20.1-10.el9_0.4.
  • Update redhat nginx-mod-stream to version 1:1.20.1-10.el9_0.4.
Affected software
Ecosystem VendorProductAffected versions
Red Hat:rhel_e4s:9.0::appstream redhat nginx < 1:1.20.1-10.el9_0.4
Fix: upgrade to 1:1.20.1-10.el9_0.4
Red Hat:rhel_e4s:9.0::appstream redhat nginx-all-modules < 1:1.20.1-10.el9_0.4
Fix: upgrade to 1:1.20.1-10.el9_0.4
Red Hat:rhel_e4s:9.0::appstream redhat nginx-filesystem < 1:1.20.1-10.el9_0.4
Fix: upgrade to 1:1.20.1-10.el9_0.4
Red Hat:rhel_e4s:9.0::appstream redhat nginx-mod-http-image-filter < 1:1.20.1-10.el9_0.4
Fix: upgrade to 1:1.20.1-10.el9_0.4
Red Hat:rhel_e4s:9.0::appstream redhat nginx-mod-http-perl < 1:1.20.1-10.el9_0.4
Fix: upgrade to 1:1.20.1-10.el9_0.4
Red Hat:rhel_e4s:9.0::appstream redhat nginx-mod-http-xslt-filter < 1:1.20.1-10.el9_0.4
Fix: upgrade to 1:1.20.1-10.el9_0.4
Red Hat:rhel_e4s:9.0::appstream redhat nginx-mod-mail < 1:1.20.1-10.el9_0.4
Fix: upgrade to 1:1.20.1-10.el9_0.4
Red Hat:rhel_e4s:9.0::appstream redhat nginx-mod-stream < 1:1.20.1-10.el9_0.4
Fix: upgrade to 1:1.20.1-10.el9_0.4
Published: 16 May 2026 · Updated: 21 May 2026 · First seen: 21 May 2026