Multiple Nginx Vulnerabilities Affect Oracle Linux Versions

Multiple Nginx Vulnerabilities Affect Oracle Linux Versions

First seen 27 Aug 2026, 13:30 UTC Linuxsecurity 69.0

Article Content

Browse articles
ThreatCluster

Recent advisories detail multiple vulnerabilities in Nginx across Oracle Linux versions 8, 9, and 10, including CVE-2026-60005 and CVE-2026-56434, which could lead to memory disclosure and denial of service. These vulnerabilities are particularly concerning as they allow for remote denial of service attacks via crafted HTTP/2 headers and memory corruption. Oracle Linux 8 and 9 users are advised to update to patched versions to mitigate risks associated with these vulnerabilities. The vulnerabilities were disclosed between March and July 2026, with some having proof-of-concept (PoC) code available. The advisories emphasize the urgency of applying patches due to the potential for exploitation. The affected Nginx versions include 1.24 and 1.26, with specific CVEs linked to each version. Current status indicates that patches are available, but the risk remains high until all users apply these updates.

Key Points: • Critical vulnerabilities in Nginx affect Oracle Linux 8, 9, and 10. • CVE-2026-60005 and CVE-2026-56434 allow for remote denial of service and memory disclosure. • Patches are available, but exploitation risk remains until updates are applied.

Timeline

2026-03-24
Multiple CVEs published
CVE-2026-27651, CVE-2026-27654, and CVE-2026-32647 disclosed, affecting Nginx.
Linuxsecurity
2026-03-24
CVE-2026-27651 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-03-24
CVE-2026-27784 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-03-24
CVE-2026-27654 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-03-24
CVE-2026-32647 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-05-13
CVE-2026-42945 published
A vulnerability allowing arbitrary code execution was disclosed for Nginx.
Linuxsecurity
2026-05-22
CVE-2026-9256 published
A vulnerability leading to denial of service was disclosed, with PoC available shortly after.
Linuxsecurity
2026-06-17
CVE-2026-42055 published
Heap-based buffer overflow vulnerability disclosed, allowing potential denial of service.
Linuxsecurity
2026-07-15
CVE-2026-60005 and CVE-2026-56434 published
Two critical vulnerabilities affecting memory disclosure and denial of service were disclosed.
Linuxsecurity
2026-08-27
Patches released for Oracle Linux
Oracle released patches for affected Nginx versions, urging users to update immediately.
Linuxsecurity