[CLSA-2026:1789729116] nginx: Fix of CVE-2026-1642
Type:
security
Severity:
Important
Release date:
2026-09-19 00:47:06 UTC
Description:
- CVE-2026-1642: reject a plain text response read from an SSL-enabled upstream before the TLS handshake has started, preventing data injection by a man-in-the-middle on the upstream connection
CVEs fixed:
Updated packages:
  • nginx-1.20.1-10.el7.tuxcare.els8.x86_64.rpm
    sha:5284fe86f9b6b5e4b51f314d8a4332f1c21a2621c83930b6bca3cdffed65aa67
  • nginx-all-modules-1.20.1-10.el7.tuxcare.els8.noarch.rpm
    sha:ed23dd069aa9aa55b786372ee15e896d6f98493314adc40d3c25130be72fd0ba
  • nginx-filesystem-1.20.1-10.el7.tuxcare.els8.noarch.rpm
    sha:3a6d3f0f98a775fa2a10b220a40c50d1125559deaa1e3a2e885fb4bc249930f8
  • nginx-mod-devel-1.20.1-10.el7.tuxcare.els8.x86_64.rpm
    sha:f2db7c54cc8aebb9f8c3448b393633e7c011b59b0058ebe5b92c59d57164985f
  • nginx-mod-http-image-filter-1.20.1-10.el7.tuxcare.els8.x86_64.rpm
    sha:ca3ebd35fcb2cc3f9052b94ad027870786b1cce50309e201fbcf34ca55b20bdb
  • nginx-mod-http-perl-1.20.1-10.el7.tuxcare.els8.x86_64.rpm
    sha:170e84ea7c628337d1fb946702911fbbef7c7ab5971150f8190d95927437ca0c
  • nginx-mod-http-xslt-filter-1.20.1-10.el7.tuxcare.els8.x86_64.rpm
    sha:d6ecfedf70f7dc4e45a8d3a8ca93b743444c4794e08c99c171c0ea13b4d92f6b
  • nginx-mod-mail-1.20.1-10.el7.tuxcare.els8.x86_64.rpm
    sha:e5862602db1819371ab2b31725c07c85236e2a30719e4aa7546cb254e7e1c588
  • nginx-mod-stream-1.20.1-10.el7.tuxcare.els8.x86_64.rpm
    sha:930d450bccb06a174ed2ed7dad107f8eb37f1b2c32b2f4b701273f3500574753
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.