Linuxsecurity
Nginx Denial of Service Vulnerability and Regression Issues
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A vulnerability in nginx was discovered that allows remote attackers to cause excessive resource consumption through specially crafted HTTP/2 cookie headers, leading to denial of service (CVE-2026-49975). The initial fix for this vulnerability introduced a regression causing nginx to crash when used with external modules. This regression has prompted a reversion of the fix pending further investigation. Affected systems include multiple Ubuntu LTS versions, specifically 26.04, 25.10, 24.04, and 22.04. Users are advised to update their systems to mitigate the risk. The vulnerability was published on June 8, 2026, with a proof of concept available since June 4, 2026. The situation is ongoing, with further updates expected.
Key Points: • Nginx vulnerability allows denial of service via crafted HTTP/2 cookie headers. • Regression from a fix caused nginx to crash when using external modules. • Affected Ubuntu versions include 26.04 LTS and earlier releases.