Red Hat Product Errata RHSA-2026:29151 - Security Advisory Issued: 2026-06-24 Updated: 2026-06-24 RHSA-2026:29151 - Security Advisory Overview Updated Packages Synopsis Important: nginx:1.26 security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for the nginx:1.26 module is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description nginx is a web and proxy server supporting HTTP and other protocols, with a focus on high concurrency, performance, and low memory usage. Security Fix(es): nginx: ngx_http_rewrite_module: code execution and denial of service (CVE-2026-9256) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 9 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.8 x86_64 Red Hat Enterprise Linux for IBM z Systems 9 s390x Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.8 s390x Red Hat Enterprise Linux for Power, little endian 9 ppc64le Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.8 ppc64le Red Hat Enterprise Linux for ARM 64 9 aarch64 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.8 aarch64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.8 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.8 x86_64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.8 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.8 s390x Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.8 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.8 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.8 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.8 s390x Fixes BZ - 2480746 - CVE-2026-9256 nginx: ngx_http_rewrite_module: code execution and denial of service CVEs CVE-2026-9256 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 9 SRPM nginx-1.26.3-9.module+el9.8.0+24374+c0e15309.1.src.rpm SHA-256: 0e90c15ed52980ee7b3cd62538c9064f1af9f76f3221e4faa9163a4719f7b173 x86_64 nginx-all-modules-1.26.3-9.module+el9.8.0+24374+c0e15309.1.noarch.rpm SHA-256: a7df1e196ee66d2196f3117e7776999aad317d216843c741aadb8db06347a8b5 nginx-filesystem-1.26.3-9.module+el9.8.0+24374+c0e15309.1.noarch.rpm SHA-256: 7b29dfbc55b4aefef16cb0444fb867b03e350eef951d448845d89a81118d5039 nginx-all-modules-1.26.3-9.module+el9.8.0+24374+c0e15309.1.noarch.rpm SHA-256: a7df1e196ee66d2196f3117e7776999aad317d216843c741aadb8db06347a8b5 nginx-filesystem-1.26.3-9.module+el9.8.0+24374+c0e15309.1.noarch.rpm SHA-256: 7b29dfbc55b4aefef16cb0444fb867b03e350eef951d448845d89a81118d5039 nginx-all-modules-1.26.3-9.module+el9.8.0+24374+c0e15309.1.noarch.rpm SHA-256: a7df1e196ee66d2196f3117e7776999aad317d216843c741aadb8db06347a8b5 nginx-filesystem-1.26.3-9.module+el9.8.0+24374+c0e15309.1.noarch.rpm SHA-256: 7b29dfbc55b4aefef16cb0444fb867b03e350eef951d448845d89a81118d5039 nginx-1.26.3-9.module+el9.8.0+24374+c0e15309.1.x86_64.rpm SHA-256: 0bf84a5a78367401088391a6818cbb1ef7edc3a3c1def42ed8d4a8d61e25bd05 nginx-all-modules-1.26.3-9.module+el9.8.0+24374+c0e15309.1.noarch.rpm SHA-256: a7df1e196ee66d2196f3117e7776999aad317d216843c741aadb8db06347a8b5 nginx-core-1.26.3-9.module+el9.8.0+24374+c0e15309.1.x86_64.rpm SHA-256: 87e85db75ecd6beca7ec2b986b91ce5a730326ef5a38e97046d2559cb5c02ac2 nginx-core-debuginfo-1.26.3-9.module+el9.8.0+24374+c0e15309.1.x86_64.rpm SHA-256: 5de5636d6020520d27e3332b09af50208a731a465218b7fc133951f3423d69ee nginx-debuginfo-1.26.3-9.module+el9.8.0+24374+c0e15309.1.x86_64.rpm SHA-256: bc6a74b4040c34affd75ddd7c3c78e0e3e09dd92395daed6ea546c4323271539 nginx-debugsource-1.26.3-9.module+el9.8.0+24374+c0e15309.1.x86_64.rpm SHA-256: b558b51d3cd4aa6ff47d3cfbfdbf4e9871b45720fb7d54f438bd4b4a73367e0c nginx-filesystem-1.26.3-9.module+el9.8.0+24374+c0e15309.1.noarch.rpm SHA-256: 7b29dfbc55b4aefef16cb0444fb867b03e350eef951d448845d89a81118d5039 nginx-mod-devel-1.26.3-9.module+el9.8.0+24374+c0e15309.1.x86_64.rpm SHA-256: 199d4f967b812450b9b02c2422a57d99ea21b7a71bd1921f20d264559e00e713 nginx-mod-http-image-filter-1.26.3-9.module+el9.8.0+24374+c0e15309.1.x86_64.rpm SHA-256: 434283fcd083cae1cc4ff2cb2097702bc193b1e212e14883d178ed4f8b9ddb93 nginx-mod-http-image-filter-debuginfo-1.26.3-9.module+el9.8.0+24374+c0e15309.1.x86_64.rpm SHA-256: b34097b3f5248f0d06a9b8c3a748c3c9a97b925fa63a86ad5ac04fcd19659d90 nginx-mod-http-perl-1.26.3-9.module+el9.8.0+24374+c0e15309.1.x86_64.rpm SHA-256: c27c3edeb1ac91cf1e02832ce7a973ec4bf8452ff8e49e038e99fc3502c03b4c nginx-mod-http-perl-debuginfo-1.26.3-9.module+el9.8.0+24374+c0e15309.1.x86_64.rpm SHA-256: ba0dafece965086faebd939d97f1aea34035a1f15721818099bb5613420e7bb4 nginx-mod-http-xslt-filter-1.26.3-9.module+el9.8.0+24374+c0e15309.1.x86_64.rpm SHA-256: 7cc14d3a2c80cc948fa24bac58cd79101c674e72e3ce53932855a22d87a781be nginx-mod-http-xslt-filter-debuginfo-1.26.3-9.module+el9.8.0+24374+c0e15309.1.x86_64.rpm SHA-256: 926ca3db786d29d7222dbd48a3717339e4682c176f1e0d013d393a26483fa60c nginx-mod-mail-1.26.3-9.module+el9.8.0+24374+c0e15309.1.x86_64.rpm SHA-256: 6974cc0192abcf4f9412e7ba59f947d89eece16f7d78e1a38eb015bc333b2999 nginx-mod-mail-debuginfo-1.26.3-9.module+el9.8.0+24374+c0e15309.1.x86_64.rpm SHA-256: 14cccb4ac1dacb0562819b590ddef79ffbd14ac3ff37245c975a61c0b4977521 nginx-mod-stream-1.26.3-9.module+el9.8.0+24374+c0e15309.1.x86_64.rpm SHA-256: ce61647cbfb917f7addb2b1f42fe38d979cc38e4f07438807f8bb8587992319a nginx-mod-stream-debuginfo-1.26.3-9.module+el9.8.0+24374+c0e15309.1.x86_64.rpm SHA-256: b46b3676a85a885d42be407c7d978dca3fde76b9740680afa6cc69d616470f4f Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.8 SRPM nginx-1.26.3-9.module+el9.8.0+24374+c0e15309.1.src.rpm SHA-256: 0e90c15ed52980ee7b3cd62538c9064f1af9f76f3221e4faa9163a4719f7b173 x86_64 nginx-all-modules-1.26.3-9.module+el9.8.0+24374+c0e15309.1.noarch.rpm SHA-256: a7df1e196ee66d2196f3117e7776999aad317d216843c741aadb8db06347a8b5 nginx-filesystem-1.26.3-9.module+el9.8.0+24374+c0e15309.1.noarch.rpm SHA-256: 7b29dfbc55b4aefef16cb0444fb867b03e350eef951d448845d89a81118d5039 nginx-all-modules-1.26.3-9.module+el9.8.0+24374+c0e15309.1.noarch.rpm SHA-256: a7df1e196ee66d2196f3117e7776999aad317d216843c741aadb8db06347a8b5 nginx-filesystem-1.26.3-9.module+el9.8.0+24374+c0e15309.1.noarch.rpm SHA-256: 7b29dfbc55b4aefef16cb0444fb867b03e350eef951d448845d89a81118d5039 nginx-all-modules-1.26.3-9.module+el9.8.0+24374+c0e15309.1.noarch.rpm SHA-256: a7df1e196ee66d2196f3117e7776999aad317d216843c741aadb8db06347a8b5 nginx-filesystem-1.26.3-9.module+el9.8.0+24374+c0e15309.1.noarch.rpm SHA-256: 7b29dfbc55b4aefef16cb0444fb867b03e350eef951d448845d89a81118d5039 nginx-1.26.3-9.module+el9.8.0+24374+c0e15309.1.x86_64.rpm SHA-256: 0bf84a5a78367401088391a6818cbb1ef7edc3a3c1def42ed8d4a8d61e25bd05 nginx-all-modules-1.26.3-9.module+el9.8.0+24374+c0e15309.1.noarch.rpm SHA-256: a7df1e196ee66d2196f3117e7776999aad317d216843c741aadb8db06347a8b5 nginx-core-1.26.3-9.module+el9.8.0+24374+c0e15309.1.x86_64.rpm SHA-256: 87e85db75ecd6beca7ec2b986b91ce5a730326ef5a38e97046d2559cb5c02ac2 nginx-core-debuginfo-1.26.3-9.module+el9.8.0+24374+c0e15309.1.x86_64.rpm SHA-256: 5de5636d6020520d27e3332b09af50208a731a465218b7fc133951f3423d69ee nginx-debuginfo-1.26.3-9.module+el9.8.0+24374+c0e15309.1.x86_64.rpm SHA-256: bc6a74b4040c34affd75ddd7c3c78e0e3e09dd92395daed6ea546c4323271539 nginx-debugsource-1.26.3-9.module+el9.8.0+24374+c0e15309.1.x86_64.rpm SHA-256: b558b51d3cd4aa6ff47d3cfbfdbf4e9871b45720fb7d54f438bd4b4a73367e0c nginx-filesystem-1.26.3-9.module+el9.8.0+24374+c0e15309.1.noarch.rpm SHA-256: 7b29dfbc55b4aefef16cb0444fb867b03e350eef951d448845d89a81118d5039 nginx-mod-devel-1.26.3-9.module+el9.8.0+24374+c0e15309.1.x86_64.rpm SHA-256: 199d4f967b812450b9b02c2422a57d99ea21b7a71bd1921f20d264559e00e713 nginx-mod-http-image-filter-1.26.3-9.module+el9.8.0+24374+c0e15309.1.x86_64.rpm SHA-256: 434283fcd083cae1cc4ff2cb2097702bc193b1e212e14883d178ed4f8b9ddb93 nginx-mod-http-image-filter-debuginfo-1.26.3-9.module+el9.8.0+24374+c0e15309.1.x86_64.rpm SHA-256: b34097b3f5248f0d06a9b8c3a748c3c9a97b925fa63a86ad5ac04fcd19659d90 nginx-mod-http-perl-1.26.3-9.module+el9.8.0+24374+c0e15309.1.x86_64.rpm SHA-256: c27c3edeb1ac91cf1e02832ce7a973ec4bf8452ff8e49e038e99fc3502c03b4c nginx-mod-http-perl-debuginfo-1.26.3-9.module+el9.8.0+24374+c0e15309.1.x86_64.rpm SHA-256: ba0dafece965086faebd939d97f1aea34035a1f15721818099bb5613420e7bb4 nginx-mod-http-xslt-filter-1.26.3-9.module+el9.8.0+24374+c0e15309.1.x86_64.rpm SHA-256: 7cc14d3a2c80cc948fa24bac58cd79101c674e72e3ce53932855a22d87a781be nginx-mod-http-xslt-filter-debuginfo-1.26.3-9.module+el9.8.0+24374+c0e15309.1.x86_64.rpm SHA-256: 926ca3db786d29d7222dbd48a3717339e4682c176f1e0d013d393a26483fa60c nginx-mod-mail-1.26.3-9.module+el9.8.0+24374+c0e15309.1.x86_64.rpm SHA-256: 6974cc0192abcf4f9412e7ba59f947d89eece16f7d78e1a38eb015bc333b2999 nginx-mod-mail-debuginfo-1.26.3-9.module+el9.8.0+24374+c0e15309.1.x86_64.rpm SHA-256: 14cccb4ac1dacb0562819b590ddef79ffbd14ac3ff37245c975a61c0b4977521 nginx-mod-stream-1.26.3-9.module+el9.8.0+24374+c0e15309.1.x86_64.rpm SHA-256: ce61647cbfb917f7addb2
A vulnerability (CVE-2026-9256, CVSS 8.1 HIGH) in the `ngx_http_rewrite_module` of nginx allows for remote code execution and denial of service. The affected versions are F5 nginx Open Source from 0.1.17 through 1.30.1, plus version 1.31.0, and F5 nginx Plus from r32 through r36 and version 37.0.0. The fixed version for nginx Plus is 37.0.1.1.