Skip to content
openSUSE NGINX Important Buffer Overflow DoS Vuln 2026-21439

openSUSE NGINX Important Buffer Overflow DoS Vuln 2026-21439

Linuxsecurity LinuxSecurity Advisories July 26, 2026

Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges ×

This update for nginx fixes the following issues

- CVE-2026-40460: bypass of authorization and bypass of rate limiting when NGINX is configured to use the HTTP/3 QUIC module (bsc#1265228).

- CVE-2026-42055: heap-based buffer overflow in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules (bsc#1268492).

- CVE-2026-48142: heap buffer over-read in the ngx_http_charset_module module (bsc#1268495).

- HTTP2-BOMB denial of service (bsc#1267525).

To install this openSUSE security update use the suse recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

zypper in -t patch openSUSE-Leap-16.0-1343=1

- openSUSE Leap 16.0:

nginx-1.27.2-160000.6.1

nginx-source-1.27.2-160000.6.1

*

*

*

Get the latest Linux and open source security news straight to your inbox.

Extracted Entities