[CLSA-2026:1789729568] nginx: Fix of CVE-2026-1642
Type:
security
Severity:
Important
Release date:
2026-09-18 11:06:18 UTC
Description:
- CVE-2026-1642: reject a plain text response read from an SSL-enabled upstream before the TLS handshake has started, preventing data injection by a man-in-the-middle on the upstream connection
CVEs fixed:
Updated packages:
  • nginx-1.20.1-10.el7.tuxcare.els8.x86_64.rpm
    sha:dec70c3fa8a616c8cc866456d4c127b8d88a995dae7b5b55d60a49ae124d415a
  • nginx-all-modules-1.20.1-10.el7.tuxcare.els8.noarch.rpm
    sha:6aea2a05de1fb71f9fa2bf6f5de6ac2180bab065eb31e31287ad3ac464741c7c
  • nginx-filesystem-1.20.1-10.el7.tuxcare.els8.noarch.rpm
    sha:c9435ab02e483eb84511e4278b86398717a55a5bede1826f7b4aab62f9026ed0
  • nginx-mod-devel-1.20.1-10.el7.tuxcare.els8.x86_64.rpm
    sha:c0d955936b050a03d2b9d55ec8b9da02b56605d25419f8004a4bcae2023ebe9c
  • nginx-mod-http-image-filter-1.20.1-10.el7.tuxcare.els8.x86_64.rpm
    sha:a371dadea0902cbc4743f05d3b61d84e8f31030b32031d2f5b00196b2a2c1313
  • nginx-mod-http-perl-1.20.1-10.el7.tuxcare.els8.x86_64.rpm
    sha:78840aca7ca3011fba707e65a218d4988466b4dd6ac693431c2bcdae0fe85ebf
  • nginx-mod-http-xslt-filter-1.20.1-10.el7.tuxcare.els8.x86_64.rpm
    sha:123445b1275878fb86bcb00c4efad160abc6f68261059d3e96d60467a295fa3c
  • nginx-mod-mail-1.20.1-10.el7.tuxcare.els8.x86_64.rpm
    sha:7d297e382d6dfb7e0216ab8d81006277740b2fadaaf981056f13efadace637a4
  • nginx-mod-stream-1.20.1-10.el7.tuxcare.els8.x86_64.rpm
    sha:ce6801b5463eda52ee5b8d5e35c976784845e4fa221228106cd10d18644f8673
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.