[CLSA-2026:1789729184] nginx: Fix of CVE-2026-1642
Type:
security
Severity:
Important
Release date:
2026-09-18 10:59:53 UTC
Description:
- CVE-2026-1642: reject a plain text response read from an SSL-enabled upstream before the TLS handshake has started, preventing data injection by a man-in-the-middle on the upstream connection
CVEs fixed:
Updated packages:
  • nginx-1.20.1-10.el7.tuxcare.els8.x86_64.rpm
    sha:e5357521bf1fea48c9d6b9585776b7d56add6312a8d857f019223f83c866b4a5
  • nginx-all-modules-1.20.1-10.el7.tuxcare.els8.noarch.rpm
    sha:b206faacd761452f12f5e2f00f4a88b6285077d694ceb2f422edae1ae5672c65
  • nginx-filesystem-1.20.1-10.el7.tuxcare.els8.noarch.rpm
    sha:b37f608f3252e890324fb076e60be7537d1b33436eacab6cd751999b471ea43c
  • nginx-mod-devel-1.20.1-10.el7.tuxcare.els8.x86_64.rpm
    sha:6094610f45d6f1a121128dab1000cb078605419ae22047deb7c32f07b53ee7f6
  • nginx-mod-http-image-filter-1.20.1-10.el7.tuxcare.els8.x86_64.rpm
    sha:9313a81802553ade449cc9e0f54b32e2b78d2380f2d0d969ece3234207580a54
  • nginx-mod-http-perl-1.20.1-10.el7.tuxcare.els8.x86_64.rpm
    sha:2c44719a89e354f4c2842b5eaa26be85bbbc5b6a8291c3ca586db821729fe6b6
  • nginx-mod-http-xslt-filter-1.20.1-10.el7.tuxcare.els8.x86_64.rpm
    sha:282f7c79a7928f481ddefa03d35e85e464871893aebf695aa1b7cdbad7ea162b
  • nginx-mod-mail-1.20.1-10.el7.tuxcare.els8.x86_64.rpm
    sha:9a0efe201f17178795293b946e1fa39f15c959c129b562c7d43f0f71f7147b2b
  • nginx-mod-stream-1.20.1-10.el7.tuxcare.els8.x86_64.rpm
    sha:69ad6809e33168a7c2c5039f7b8301dd052576a174b6ebe20a95f7e43fdfbb80
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.