RHSA-2026:19371: Critical: nginx:1.24 security update
Critical: nginx:1.24 security update
Other sources
nginx is a web and proxy server supporting HTTP and other protocols, with a focus on high concurrency, performance, and low memory usage. Security Fix(es): nginx: NGINX: Arbitrary Code Execution Vulnerability (CVE-2026-42945) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/nginxto a version that resolves this vulnerability.Fixed in 1.24.0-7.module+el9.8.0+24289+833e4c02.1 - Upgrade
Upgrade
redhat/nginx-all-modulesto a version that resolves this vulnerability.Fixed in 1.24.0-7.module+el9.8.0+24289+833e4c02.1 - Upgrade
Upgrade
redhat/nginx-filesystemto a version that resolves this vulnerability.Fixed in 1.24.0-7.module+el9.8.0+24289+833e4c02.1 - Upgrade
Upgrade
redhat/nginx-coreto a version that resolves this vulnerability.Fixed in 1.24.0-7.module+el9.8.0+24289+833e4c02.1 - Upgrade
Upgrade
redhat/nginx-core-debuginfoto a version that resolves this vulnerability.Fixed in 1.24.0-7.module+el9.8.0+24289+833e4c02.1 - Upgrade
Upgrade
redhat/nginx-debuginfoto a version that resolves this vulnerability.Fixed in 1.24.0-7.module+el9.8.0+24289+833e4c02.1 - Upgrade
Upgrade
redhat/nginx-debugsourceto a version that resolves this vulnerability.Fixed in 1.24.0-7.module+el9.8.0+24289+833e4c02.1 - Upgrade
Upgrade
redhat/nginx-mod-develto a version that resolves this vulnerability.Fixed in 1.24.0-7.module+el9.8.0+24289+833e4c02.1 - Upgrade
Upgrade
redhat/nginx-mod-http-image-filterto a version that resolves this vulnerability.Fixed in 1.24.0-7.module+el9.8.0+24289+833e4c02.1 - Upgrade
Upgrade
redhat/nginx-mod-http-image-filter-debuginfoto a version that resolves this vulnerability.Fixed in 1.24.0-7.module+el9.8.0+24289+833e4c02.1 - Upgrade
Upgrade
redhat/nginx-mod-http-perlto a version that resolves this vulnerability.Fixed in 1.24.0-7.module+el9.8.0+24289+833e4c02.1 - Upgrade
Upgrade
redhat/nginx-mod-http-perl-debuginfoto a version that resolves this vulnerability.Fixed in 1.24.0-7.module+el9.8.0+24289+833e4c02.1 - Upgrade
Upgrade
redhat/nginx-mod-http-xslt-filterto a version that resolves this vulnerability.Fixed in 1.24.0-7.module+el9.8.0+24289+833e4c02.1 - Upgrade
Upgrade
redhat/nginx-mod-http-xslt-filter-debuginfoto a version that resolves this vulnerability.Fixed in 1.24.0-7.module+el9.8.0+24289+833e4c02.1 - Upgrade
Upgrade
redhat/nginx-mod-mailto a version that resolves this vulnerability.Fixed in 1.24.0-7.module+el9.8.0+24289+833e4c02.1 - Upgrade
Upgrade
redhat/nginx-mod-mail-debuginfoto a version that resolves this vulnerability.Fixed in 1.24.0-7.module+el9.8.0+24289+833e4c02.1 - Upgrade
Upgrade
redhat/nginx-mod-streamto a version that resolves this vulnerability.Fixed in 1.24.0-7.module+el9.8.0+24289+833e4c02.1 - Upgrade
Upgrade
redhat/nginx-mod-stream-debuginfoto a version that resolves this vulnerability.Fixed in 1.24.0-7.module+el9.8.0+24289+833e4c02.1 - Upgrade
Upgrade
redhat/nginxto a version that resolves this vulnerability.Fixed in 1.24.0-7.module+el9.8.0+24289+833e4c02.1.aa - Upgrade
Upgrade
redhat/nginx-coreto a version that resolves this vulnerability.Fixed in 1.24.0-7.module+el9.8.0+24289+833e4c02.1.aa - Upgrade
Upgrade
redhat/nginx-core-debuginfoto a version that resolves this vulnerability.Fixed in 1.24.0-7.module+el9.8.0+24289+833e4c02.1.aa - Upgrade
Upgrade
redhat/nginx-debuginfoto a version that resolves this vulnerability.Fixed in 1.24.0-7.module+el9.8.0+24289+833e4c02.1.aa - Upgrade
Upgrade
redhat/nginx-debugsourceto a version that resolves this vulnerability.Fixed in 1.24.0-7.module+el9.8.0+24289+833e4c02.1.aa - Upgrade
Upgrade
redhat/nginx-mod-develto a version that resolves this vulnerability.Fixed in 1.24.0-7.module+el9.8.0+24289+833e4c02.1.aa - Upgrade
Upgrade
redhat/nginx-mod-http-image-filterto a version that resolves this vulnerability.Fixed in 1.24.0-7.module+el9.8.0+24289+833e4c02.1.aa - Upgrade
Upgrade
redhat/nginx-mod-http-image-filter-debuginfoto a version that resolves this vulnerability.Fixed in 1.24.0-7.module+el9.8.0+24289+833e4c02.1.aa - Upgrade
Upgrade
redhat/nginx-mod-http-perlto a version that resolves this vulnerability.Fixed in 1.24.0-7.module+el9.8.0+24289+833e4c02.1.aa - Upgrade
Upgrade
redhat/nginx-mod-http-perl-debuginfoto a version that resolves this vulnerability.Fixed in 1.24.0-7.module+el9.8.0+24289+833e4c02.1.aa - Upgrade
Upgrade
redhat/nginx-mod-http-xslt-filterto a version that resolves this vulnerability.Fixed in 1.24.0-7.module+el9.8.0+24289+833e4c02.1.aa - Upgrade
Upgrade
redhat/nginx-mod-http-xslt-filter-debuginfoto a version that resolves this vulnerability.Fixed in 1.24.0-7.module+el9.8.0+24289+833e4c02.1.aa - Upgrade
Upgrade
redhat/nginx-mod-mailto a version that resolves this vulnerability.Fixed in 1.24.0-7.module+el9.8.0+24289+833e4c02.1.aa - Upgrade
Upgrade
redhat/nginx-mod-mail-debuginfoto a version that resolves this vulnerability.Fixed in 1.24.0-7.module+el9.8.0+24289+833e4c02.1.aa - Upgrade
Upgrade
redhat/nginx-mod-streamto a version that resolves this vulnerability.Fixed in 1.24.0-7.module+el9.8.0+24289+833e4c02.1.aa - Upgrade
Upgrade
redhat/nginx-mod-stream-debuginfoto a version that resolves this vulnerability.Fixed in 1.24.0-7.module+el9.8.0+24289+833e4c02.1.aa
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:19371?
The severity of RHSA-2026:19371 is critical, with a CVSS score of 9.
What vulnerability is addressed in RHSA-2026:19371?
RHSA-2026:19371 addresses an arbitrary code execution vulnerability in nginx identified as CVE-2026-42945.
How do I fix RHSA-2026:19371?
To fix RHSA-2026:19371, you should update to the patched version of nginx 1.24.0-7 or higher.
What versions of nginx are affected by RHSA-2026:19371?
RHSA-2026:19371 affects certain versions of nginx, specifically those prior to the security update version 1.24.0-7.
Is there any risk if I do not address RHSA-2026:19371?
Yes, not addressing RHSA-2026:19371 exposes your server to potential arbitrary code execution attacks.