[ GLSA 202608-16 ] nginx: Multiple Vulnerabilities

[email protected]
Newsgroups gmane.linux.gentoo.announce
Message-ID <178694953377.1.8581906327053280451@f5bc8f6d682b>
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory                           GLSA 202608-16
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
                                           https://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

 Severity: High
    Title: nginx: Multiple Vulnerabilities
     Date: August 17, 2026
     Bugs: #949354, #967910, #969626, #971553, #974894, #975844, #977606, #979311
       ID: 202608-16

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
========

Multiple vulnerabilities have been found in nginx, the worst of which
could result in arbitrary code execution.

Background
==========

nginx is a robust, small, and high performance HTTP and reverse proxy
server.

Affected packages
=================

Package            Vulnerable    Unaffected
-----------------  ------------  ------------
www-servers/nginx  < 1.31.3-r1   >= 1.31.3-r1

Description
===========

Multiple vulnerabilities have been discovered in nginx. Please review
the CVE identifiers referenced below for details.

Impact
======

Please review the referenced CVE identifiers for details.

Workaround
==========

There is no known workaround at this time.

Resolution
==========

All nginx users should upgrade to the latest version:

  # emerge --sync
  # emerge --ask --oneshot --verbose ">=www-servers/nginx-1.31.3-r1"

References
==========

[ 1 ] CVE-2025-23419
      https://nvd.nist.gov/vuln/detail/CVE-2025-23419
[ 2 ] CVE-2025-53859
      https://nvd.nist.gov/vuln/detail/CVE-2025-53859
[ 3 ] CVE-2026-1642
      https://nvd.nist.gov/vuln/detail/CVE-2026-1642
[ 4 ] CVE-2026-9256
      https://nvd.nist.gov/vuln/detail/CVE-2026-9256
[ 5 ] CVE-2026-27651
      https://nvd.nist.gov/vuln/detail/CVE-2026-27651
[ 6 ] CVE-2026-27654
      https://nvd.nist.gov/vuln/detail/CVE-2026-27654
[ 7 ] CVE-2026-27784
      https://nvd.nist.gov/vuln/detail/CVE-2026-27784
[ 8 ] CVE-2026-28753
      https://nvd.nist.gov/vuln/detail/CVE-2026-28753
[ 9 ] CVE-2026-28755
      https://nvd.nist.gov/vuln/detail/CVE-2026-28755
[ 10 ] CVE-2026-32647
      https://nvd.nist.gov/vuln/detail/CVE-2026-32647
[ 11 ] CVE-2026-40701
      https://nvd.nist.gov/vuln/detail/CVE-2026-40701
[ 12 ] CVE-2026-42055
      https://nvd.nist.gov/vuln/detail/CVE-2026-42055
[ 13 ] CVE-2026-42530
      https://nvd.nist.gov/vuln/detail/CVE-2026-42530
[ 14 ] CVE-2026-42533
      https://nvd.nist.gov/vuln/detail/CVE-2026-42533
[ 15 ] CVE-2026-42934
      https://nvd.nist.gov/vuln/detail/CVE-2026-42934
[ 16 ] CVE-2026-42945
      https://nvd.nist.gov/vuln/detail/CVE-2026-42945
[ 17 ] CVE-2026-42946
      https://nvd.nist.gov/vuln/detail/CVE-2026-42946
[ 18 ] CVE-2026-48142
      https://nvd.nist.gov/vuln/detail/CVE-2026-48142
[ 19 ] CVE-2026-56434
      https://nvd.nist.gov/vuln/detail/CVE-2026-56434
[ 20 ] CVE-2026-60005
      https://nvd.nist.gov/vuln/detail/CVE-2026-60005

Availability
============

This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:

 https://security.gentoo.org/glsa/202608-16

Concerns?
=========

Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users' machines is of utmost
importance to us. Any security concerns should be addressed to
[email protected] or alternatively, you may file a bug at
https://bugs.gentoo.org.

License
=======

Copyright 2026 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).

The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.

https://creativecommons.org/licenses/by-sa/2.5
signature.asc (application/pgp-signature, 870 B)
-----BEGIN PGP SIGNATURE-----

iQJPBAEBCAA5FiEEpqTA6ABLMxh/aChGFMQkOaVy+9kFAmqCr50bFIAAAAAABAAO
bWFudTIsMi41KzEuMTIsMiwyAAoJEBTEJDmlcvvZlFcP/2W1jdaA25v1DxXTlr2e
xQs3cQNfl1WYzgn34YOtxkrOS7CbYA0i4hUzczSTV0WuBdYy8c2uNgaq19N3RpAS
ETayxA8FGSRBUXjPTRiE7zKJk4EwzfWYi3LKtl0GrL7fy4u3+fZU9qWqmQDaaar0
I4B2J9rpK8d12NOPoPS6f+fqD8OaF9iUMeZ3Xub62JHcuX5+ydOYNCbqciS2sEtS
JULAolbdm5opQydi3ZdQuvPNajLmypu+wqD8zwDBsd9WBJq6Fhhd8l8713zWVOZP
f4Lmv3A9K+n4IywN5VRG7YJjYrv+IEDf0Yc5D2dIlt1ZYgWoyX+WGpFYD5XxtDyz
MOWxINb0wXL7nZW6991ZLsaiekY9uBIEmY1H+f5gnlyfxzrrZacQe9kB7Rxcf7Vj
clkVeaBV6+YHjzqAezc9+PueAjcBkyDQUNWB9KeEQoSjAGrYEexn8L4QthqK04RA
tztcYRHOruVLDHJLwaDc1da7TJmcX0KkecJXlY1mc4FMv1o0mEnzXbYPKRxuRUMw
RTPZHWeSfGOzzJQ1yEmQ1KMCijR6vSh+CfKY00aCLZ4TQK6O745TzxKckluduQvA
1LcFrCkPSgac5bQkom8GmnyLTMm0dvV6lvWsIvEgQHRxxAeQkFIWFeYL03xAF5qv
Zihf5uQxbtAbWYu0VsQ2o5or
=7cR/
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.