Critical Vulnerabilities in openSUSE NGINX Require Immediate Attention

Critical Vulnerabilities in openSUSE NGINX Require Immediate Attention

First seen 29 Jul 2026, 11:02 UTC Linuxsecurity 93% similarity 72.0

Article Content

Browse articles
ThreatCluster

Recent updates for openSUSE NGINX address multiple vulnerabilities, including CVE-2026-42055, a heap-based buffer overflow affecting the ngx_http_proxy_v2_module and ngx_http_grpc_module, and CVE-2026-48142, a heap buffer over-read in the ngx_http_charset_module. Additionally, CVE-2026-40460 allows for authorization bypass and rate limiting issues when using the HTTP/3 QUIC module. The vulnerabilities pose significant risks, including potential remote denial of service attacks via the HTTP/2 bomb exploit. Affected systems include various versions of openSUSE and SUSE Linux Enterprise Server. Administrators are advised to apply patches immediately to mitigate risks. The vulnerabilities were disclosed between May and June 2026, with patches available as of late July 2026.

Key Points: • Multiple critical vulnerabilities in openSUSE NGINX require urgent patching. • CVE-2026-42055 and CVE-2026-48142 involve serious buffer overflow issues. • CVE-2026-40460 allows for authorization bypass in HTTP/3 configurations.

ThreatCluster AI How this analysis works

Timeline

2026-05-13
CVE-2026-40460 published
Authorization bypass and rate limiting issues reported for NGINX with HTTP/3 QUIC module.
Linuxsecurity
2026-06-17
CVE-2026-42055 and CVE-2026-48142 published
Heap-based buffer overflow and heap buffer over-read vulnerabilities disclosed for NGINX.
Linuxsecurity
2026-06-19
First public PoC for CVE-2026-42055
Proof of concept for the heap-based buffer overflow vulnerability made public, increasing urgency for patching.
Date unknown
2026-07-26
Previous advisory published
Linuxsecurity published an advisory detailing vulnerabilities in openSUSE NGINX, including CVE-2026-40460.
Linuxsecurity
2026-07-28
Latest patch released
openSUSE released patches for critical vulnerabilities in NGINX, urging immediate application by users.
Linuxsecurity

Community

Browse all →