[ALSA-2026:6906] Important: nginx security update
Type:
security
Severity:
important
Release date:
2026-04-09
Description:
nginx is a web and proxy server supporting HTTP and other protocols, with a focus on high concurrency, performance, and low memory usage. Security Fix(es): * nginx: NGINX: Denial of Service or Code Execution via specially crafted MP4 files (CVE-2026-32647) * NGINX: NGINX: Denial of Service or file modification via buffer overflow in ngx_http_dav_module (CVE-2026-27654) * NGINX: NGINX: Denial of Service due to memory corruption via crafted MP4 file (CVE-2026-27784) * NGINX: NGINX: Denial of Service via undisclosed requests when ngx_mail_auth_http_module is enabled (CVE-2026-27651) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
noarch nginx-all-modules-1.26.3-2.el10_1.1.noarch.rpm 5b1c5fd70e0b1f9d47540eeb6755f33520d2463594a89378ac69c50090d13882
noarch nginx-filesystem-1.26.3-2.el10_1.1.noarch.rpm 9aee86de0234e36073a7df53cbed67bc23ce4a93482436b58b3ab7b95dd5c94e
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.