rpm package
opensuse/nginx&distro=openSUSE Leap 16.0
pkg:rpm/opensuse/nginx&distro=openSUSE%20Leap%2016.0
Vulnerabilities (5)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-42533 | Hig | 8.1 | < 1.27.2-160000.7.1 | 1.27.2-160000.7.1 | Jul 15, 2026 | A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the map's regex capture variables before referencing the map output variable. Alternatively, the same result could be achieved by using a non-cac | |
| CVE-2026-48142 | Med | 4.8 | < 1.27.2-160000.6.1 | 1.27.2-160000.6.1 | Jun 17, 2026 | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When content is served or proxied through a location block with both source_charset utf-8; and a charset directive (for example, charset koi8-r;) configured, remote, unauthenticated attac | |
| CVE-2026-42055 | Hig | 8.1 | < 1.27.2-160000.6.1 | 1.27.2-160000.6.1 | Jun 17, 2026 | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass directives are used to proxy HTTP/2 traffic, the ignore_invalid_headers directive is set | |
| CVE-2026-9256 | Hig | 8.1 | < 1.27.2-160000.5.1 | 1.27.2-160000.5.1 | May 22, 2026 | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite directive uses a regex pattern with distinct, overlapping Perl-Compatible Regular Expression (PCRE) captures (for example, ^/((.*))$) and a replac | |
| CVE-2026-40460 | Med | 6.5 | < 1.27.2-160000.6.1 | 1.27.2-160000.6.1 | May 13, 2026 | When NGINX Plus or NGINX Open Source are configured to use the HTTP/3 QUIC module, an attacker may be able to spoof their source IP address allowing for bypass of authorization or bypass of rate limiting. Note: Software versions which have reached End of Technical Support (EoTS) |
- affected < 1.27.2-160000.7.1fixed 1.27.2-160000.7.1
A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the map's regex capture variables before referencing the map output variable. Alternatively, the same result could be achieved by using a non-cac
- affected < 1.27.2-160000.6.1fixed 1.27.2-160000.6.1
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When content is served or proxied through a location block with both source_charset utf-8; and a charset directive (for example, charset koi8-r;) configured, remote, unauthenticated attac
- affected < 1.27.2-160000.6.1fixed 1.27.2-160000.6.1
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass directives are used to proxy HTTP/2 traffic, the ignore_invalid_headers directive is set
- affected < 1.27.2-160000.5.1fixed 1.27.2-160000.5.1
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite directive uses a regex pattern with distinct, overlapping Perl-Compatible Regular Expression (PCRE) captures (for example, ^/((.*))$) and a replac
- affected < 1.27.2-160000.6.1fixed 1.27.2-160000.6.1
When NGINX Plus or NGINX Open Source are configured to use the HTTP/3 QUIC module, an attacker may be able to spoof their source IP address allowing for bypass of authorization or bypass of rate limiting. Note: Software versions which have reached End of Technical Support (EoTS)