Security & Threat Intelligence · 19.08.2026, 14:16 UTC
USN-8563-3: nginx vulnerability
| Schweregrad | info |
|---|---|
| CVE | ↗ ↗ ↗ |
| Kategorie | Security & Threat Intelligence |
| Quelle | Ubuntu Security Notices ↗ |
| Veröffentlicht | 19.08.2026 UTC |
Sicherheitsmeldung mit Schweregrad noch nicht bewertet. Betroffene Kennungen: CVE-2026-42533, CVE-2026-56434, CVE-2026-60005. Technische Details im Tab „Originaltext“; empfohlene Schritte in der Checkliste.
USN-8563-1 fixed vulnerabilities in nginx. The fix for CVE-2026-42533 was backed out in USN-8563-2 because it could cause a regression. This update includes a better fix for CVE-2026-42533.
We apologize for the inconvenience.
Original advisory details:
It was discovered that nginx incorrectly handled certain map directives using regex matching and capture variables. A remote attacker could use this issue to cause nginx to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2026-42533)
It was discovered that nginx had a use-after-free vulnerability in the ngx_http_ssi_module module when configured with Server-Side Includes, proxy_pass, and proxy buffering disabled directives. An attacker able to intercept traffic and control responses from an upstream server could possibly use this issue to cause nginx to crash, resulting in a denial of service. (CVE-2026-56434)
It was discovered that nginx incorrectly handled certain requests in the ngx_http_slice_module module. A remote attacker could possibly use this issue to obtain sensitive information or cause nginx to crash, resulting in a denial of service. (CVE-2026-60005)
Maßnahmen
⬇ Als MarkdownVerwandte Beiträge
- info USN-8563-4: nginx regression
- info Amazon EC2 R8i instances are now available in Israel (Tel Aviv) region
- info Amazon EC2 R8i and R8i-Flex instances are now available in Canada West (Calgary) region
- high ZDI-26-578: NGINX HTTP Dav Module Alias Directive Integer Underflow Remote Code Execution Vulnerability