Nginx Denial of Service Vulnerability and Regression Issues

Nginx Denial of Service Vulnerability and Regression Issues

First seen 8 Jun 2026, 21:23 UTC Ubuntulaunchpad.netLinuxsecurity 91% similarity 70.5

Article Content

Browse articles
ThreatCluster

A vulnerability in nginx was discovered that allows remote attackers to cause excessive resource consumption through specially crafted HTTP/2 cookie headers, leading to denial of service (CVE-2026-49975). The initial fix for this vulnerability introduced a regression causing nginx to crash when used with external modules. This regression has prompted a reversion of the fix pending further investigation. Affected systems include multiple Ubuntu LTS versions, specifically 26.04, 25.10, 24.04, and 22.04. Users are advised to update their systems to mitigate the risk. The vulnerability was published on June 8, 2026, with a proof of concept available since June 4, 2026. The situation is ongoing, with further updates expected.

Key Points: • Nginx vulnerability allows denial of service via crafted HTTP/2 cookie headers. • Regression from a fix caused nginx to crash when using external modules. • Affected Ubuntu versions include 26.04 LTS and earlier releases.

ThreatCluster AI

Timeline

2026-06-04
First public PoC for CVE-2026-49975
A proof of concept was made available for a vulnerability in nginx affecting resource consumption.
Date unknown
2026-06-08
CVE-2026-49975 published
The vulnerability was officially published, detailing how nginx mishandled HTTP/2 cookie headers.
Ubuntu
2026-06-08
Regression issue identified
The fix for CVE-2026-49975 caused nginx to crash when used with external modules, prompting a reversion of the fix.
Ubuntu
Recent
Users advised to update systems
Affected users are encouraged to update their nginx installations to mitigate the denial of service risk.
Linuxsecurity

Community

Browse all →

Tracked Entities in This Story