gpp_maybe
Security update for nginx
SUSE-SLES-16.0-790
This update for nginx fixes the following issues: - CVE-2026-1642: plain text data injection into the response from an upstream proxied server (bsc#1257675). - CVE-2026-27654: buffer overflow in the NGINX worker process via the `ngx_http_dav_module module` (bsc#1260416). - CVE-2026-27784: NGINX worker memory over-read or over-write via a specially crafted MP4 file (bsc#1260417). - CVE-2026-28753: improper handling onf CRLF sequences in CRLF responses allows for arbitrary header injection into SMTP upstream requests (bsc#1260418). - CVE-2026-28755: TLS handshakes can succeed with revoked certificates due to improper handling of such certificates by the `ngx_stream_ssl_module` module (bsc#1260419).
-
Release DateMay 19 2026
-
ReferencesBugzilla: 1257675, 1260416, 1260417, 1260418, 1260419
CVEs: CVE-2026-1642, CVE-2026-27654, CVE-2026-27784, CVE-2026-28753, CVE-2026-28755 -
Typesecurity
-
Severityimportant
cloud_download Downloads
SUSE Linux Enterprise Server 16.0 aarch64
-
Packagesnginx
A HTTP server and IMAP/POP3 proxy servernginx-source1.27.2-160000.3.1 lock rpm
The nginx source1.27.2-160000.3.1 lock rpm
SUSE Linux Enterprise Server 16.0 ppc64le
-
Packagesnginx
A HTTP server and IMAP/POP3 proxy servernginx-source1.27.2-160000.3.1 lock rpm
The nginx source1.27.2-160000.3.1 lock rpm
SUSE Linux Enterprise Server 16.0 s390x
-
Packagesnginx
A HTTP server and IMAP/POP3 proxy servernginx-source1.27.2-160000.3.1 lock rpm
The nginx source1.27.2-160000.3.1 lock rpm
SUSE Linux Enterprise Server 16.0 x86_64
-
Packagesnginx
A HTTP server and IMAP/POP3 proxy servernginx-source1.27.2-160000.3.1 lock rpm
The nginx source1.27.2-160000.3.1 lock rpm
SUSE Linux Enterprise Server for SAP applications 16.0 ppc64le
-
Packagesnginx
A HTTP server and IMAP/POP3 proxy servernginx-source1.27.2-160000.3.1 lock rpm
The nginx source1.27.2-160000.3.1 lock rpm
SUSE Linux Enterprise Server for SAP applications 16.0 x86_64
-
Packagesnginx
A HTTP server and IMAP/POP3 proxy servernginx-source1.27.2-160000.3.1 lock rpm
The nginx source1.27.2-160000.3.1 lock rpm