-
Thu Aug 27 2026 EL Errata <el-errata_ww@oracle.com> - 1.20.1-28.0.1.el9_8.5
- Reference oracle-indexhtml within Requires [Orabug: 33802044]
- Remove Red Hat references [Orabug: 29498217]
- Update upstream references [Orabug: 36579090]
-
Mon Aug 03 2026 Luboš Uhliarik <luhliari@redhat.com> - 2:1.20.1-28.5
- Resolves: RHEL-219316 - nginx: NGINX: Heap buffer over-read allows memory
modification or denial of service (CVE-2026-56434)
- Resolves: RHEL-217969 - nginx: NGINX: Memory disclosure and denial of service
in ngx_http_slice_module (CVE-2026-60005)
-
Fri Jul 03 2026 Luboš Uhliarik <luhliari@redhat.com> - 2:1.20.1-28.4
- Resolves: RHEL-190800 - nginx: "HTTP/2 bomb" nginx fix breaks module ABI
causing crashes
- Resolves: RHEL-188418 - nginx: NGINX: Arbitrary code execution or
Denial of Service via heap-based buffer overflow with crafted HTTP/2
headers (CVE-2026-42055)
-
Mon Jun 08 2026 Luboš Uhliarik <luhliari@redhat.com> - 2:1.20.1-28.3
- Resolves: RHEL-178684 - nginx: code execution and denial of
service (CVE-2026-9256)
- Resolves: RHEL-182553 - nginx: HTTP/2: Remote Denial of Service via
compression bomb and Slowloris-style attack
-
Thu May 14 2026 Luboš Uhliarik <luhliari@redhat.com> - 2:1.20.1-28.2
- Resolves: RHEL-176232 - nginx: NGINX: Arbitrary Code Execution
Vulnerability (CVE-2026-42945)
-
Fri Mar 27 2026 Zdenek Dohnal <zdohnal@redhat.com> - 2:1.20.1-28.1
- RHEL-159560 CVE-2026-27654 nginx: NGINX: Denial of Service or file modification via buffer overflow in ngx_http_dav_module
- RHEL-159539 CVE-2026-27784 nginx: NGINX: Denial of Service due to memory corruption via crafted MP4 file
- RHEL-159447 CVE-2026-27651 nginx: NGINX: Denial of Service via undisclosed requests when ngx_mail_auth_http_module is enabled
- RHEL-157888 CVE-2026-32647 nginx: NGINX: Denial of Service or Code Execution via specially crafted MP4 files
-
Tue Feb 17 2026 Luboš Uhliarik <luhliari@redhat.com> - 2:1.20.1-28
- Resolves: RHEL-146528 - CVE-2026-1642 nginx: NGINX: Data injection via
man-in-the-middle attack on TLS proxied connection
-
Thu Jan 29 2026 Luboš Uhliarik <luhliari@redhat.com> - 2:1.20.1-27
- Resolves: RHEL-145177 - Clarify binding behavior of -t option
-
Thu Nov 20 2025 Luboš Uhliarik <luhliari@redhat.com> - 2:1.20.1-26
- Resolves: RHEL-102548 - Remove 50x.html for nginx 1.26
-
Wed Nov 19 2025 Luboš Uhliarik <luhliari@redhat.com> - 2:1.20.1-25
- Resolves: RHEL-114935 - Image mode: The dir /var/lib and /var/log
is not created when updating system in image mode