[CLSA-2026:1784807256] nginx: Fix of CVE-2026-42055
Type:
security
Severity:
Low
Release date:
2026-07-23 11:48:01 UTC
Description:
- CVE-2026-42055: limit HTTP/2 header field length in ngx_http_grpc_module to avoid heap buffer overflow when proxying to a gRPC upstream
CVEs fixed:
Updated packages:
  • nginx-1.20.1-22.el9_6.3.alma.2.tuxcare.els7.x86_64.rpm
    sha:83e39199a70bce9d214addf660721095ab026a7b193a83aabeded2bce2bdae41
  • nginx-all-modules-1.20.1-22.el9_6.3.alma.2.tuxcare.els7.noarch.rpm
    sha:5d53105f9c1e594b068249fd06071c7ed63f0f97e5d82d9bd05da49e3887fa89
  • nginx-core-1.20.1-22.el9_6.3.alma.2.tuxcare.els7.x86_64.rpm
    sha:4f13e71b5090743aee660a43d20001d1de9725870d5fd6bb49cfabc09a1cb427
  • nginx-filesystem-1.20.1-22.el9_6.3.alma.2.tuxcare.els7.noarch.rpm
    sha:7b706e318964bfe6db3754fe57aca3a9c68b958ee78a2ad6b0c9abe5ca51b2aa
  • nginx-mod-devel-1.20.1-22.el9_6.3.alma.2.tuxcare.els7.x86_64.rpm
    sha:69746c065d0b6fda31a36d5bfdfd5eb5572f6301840e5987ea146afcde7de6d9
  • nginx-mod-http-image-filter-1.20.1-22.el9_6.3.alma.2.tuxcare.els7.x86_64.rpm
    sha:94d1717a5e7bc765f23da9c04abf598658da5baac97291a2511e130ed6edb3ce
  • nginx-mod-http-perl-1.20.1-22.el9_6.3.alma.2.tuxcare.els7.x86_64.rpm
    sha:b35556483675e66d00f12ec88f43cf2aa46970e6a901d89aa1ce9149101c2f23
  • nginx-mod-http-xslt-filter-1.20.1-22.el9_6.3.alma.2.tuxcare.els7.x86_64.rpm
    sha:06136fffd49dd982373537e38a335adf25954a913abab1eaea7423759c69ba3f
  • nginx-mod-mail-1.20.1-22.el9_6.3.alma.2.tuxcare.els7.x86_64.rpm
    sha:ea5119218cac687520e3a1eaadf610c86db2d38f4d5847810e25c031a1458114
  • nginx-mod-stream-1.20.1-22.el9_6.3.alma.2.tuxcare.els7.x86_64.rpm
    sha:d201c75482af2b745456a7323618224b8a7ba9b5a3549c3b323c712281724e6e
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.