{"id":"USN-8375-1","summary":"nginx vulnerabilities","details":"It was discovered that the nginx ngx_mail_smtp_module module incorrectly\nhandled certain memory operations when doing SMTP authentication. This\ncould possibly result in sensitive information being sent to the\nauthentication server. (CVE-2025-53859)\n\nIt was discovered that nginx incorrectly handled proxying to upstream TLS\nservers. An attacker could possibly use this issue to insert plain text\ndata into the response from an upstream proxied server. (CVE-2026-1642)\n\nIt was discovered that the nginx ngx_mail_auth_http_module module\nincorrectly handled certain requests. An attacker could possibly use this\nissue to cause nginx to crash, resulting in a denial of service.\n(CVE-2026-27651)\n\nIt was discovered that the nginx ngx_http_dav_module module incorrectly\nhandled certain destination URIs. An attacker could use this issue to cause\nnginx to crash, resulting in a denial of service, or possibly modify source\nor destination names outside of the document root. (CVE-2026-27654)\n\nIt was discovered that the nginx ngx_http_mp4_module module incorrectly\nhandled certain MP4 files. An attacker could use this issue to cause nginx\nto crash, resulting in a denial of service, or possibly execute arbitrary\ncode. (CVE-2026-27784, CVE-2026-32647)\n\nIt was discovered that the nginx ngx_mail_smtp_module module incorrectly\nhandled certain CRLF sequences. An attacker could possibly use this issue\nto inject arbitrary SMTP headers. (CVE-2026-28753)\n\nIt was discovered that nginx contained a use-after-free vulnerability in\nthe ngx_http_ssl_module module when client certificate verification and\nOCSP validation were enabled. A remote attacker could use this issue to\ncause nginx to crash, resulting in a denial of service, or possibly modify\ndata in memory. (CVE-2026-40701)\n\nIt was discovered that nginx did not properly handle certain proxied\nresponses in the ngx_http_charset_module module. A remote attacker could\npossibly use this issue to obtain sensitive information or cause nginx to\ncrash, resulting in a denial of service. (CVE-2026-42934)\n\nIt was discovered that the nginx ngx_http_rewrite_module component\nincorrectly handled certain rewrite directives. A remote attacker could use\nthis issue to cause nginx to crash, resulting in a denial of service, or\npossibly execute arbitrary code. (CVE-2026-42945)\n\nIt was discovered that nginx did not properly process certain SCGI and\nuWSGI responses. An attacker able to perform a machine-in-the-middle attack\ncould possibly use this issue to obtain sensitive information or cause\nnginx to crash, resulting in a denial of service. (CVE-2026-42946)\n\nIt was discovered that nginx incorrectly handled certain rewrite rules in\nthe ngx_http_rewrite_module module. A remote attacker could use this issue\nto cause nginx to crash, resulting in a denial of service, or possibly\nexecute arbitrary code. (CVE-2026-9256)","modified":"2026-06-30T18:17:07.148587773Z","published":"2026-06-03T07:11:56Z","related":["UBUNTU-CVE-2025-53859","UBUNTU-CVE-2026-1642","UBUNTU-CVE-2026-27651","UBUNTU-CVE-2026-27654","UBUNTU-CVE-2026-27784","UBUNTU-CVE-2026-28753","UBUNTU-CVE-2026-32647","UBUNTU-CVE-2026-40701","UBUNTU-CVE-2026-42934","UBUNTU-CVE-2026-42945","UBUNTU-CVE-2026-42946","UBUNTU-CVE-2026-9256"],"upstream":["UBUNTU-CVE-2025-53859","UBUNTU-CVE-2026-1642","UBUNTU-CVE-2026-9256","UBUNTU-CVE-2026-27651","UBUNTU-CVE-2026-27654","UBUNTU-CVE-2026-27784","UBUNTU-CVE-2026-28753","UBUNTU-CVE-2026-32647","UBUNTU-CVE-2026-40701","UBUNTU-CVE-2026-42934","UBUNTU-CVE-2026-42945","UBUNTU-CVE-2026-42946"],"references":[{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-8375-1"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2025-53859"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-1642"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-9256"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-27651"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-27654"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-27784"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-28753"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-32647"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-40701"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-42934"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-42945"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-42946"}],"affected":[{"package":{"name":"nginx","ecosystem":"Ubuntu:Pro:14.04:LTS","purl":"pkg:deb/ubuntu/nginx?arch=source&distro=esm-infra-legacy%2Ftrusty"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.4.6-1ubuntu3.9+esm6"}]}],"versions":["1.4.1-3ubuntu1","1.4.3-2ubuntu1","1.4.4-1ubuntu1","1.4.4-2ubuntu1","1.4.4-4ubuntu1","1.4.5-1ubuntu1","1.4.6-1ubuntu2","1.4.6-1ubuntu3","1.4.6-1ubuntu3.1","1.4.6-1ubuntu3.2","1.4.6-1ubuntu3.3","1.4.6-1ubuntu3.4","1.4.6-1ubuntu3.5","1.4.6-1ubuntu3.6","1.4.6-1ubuntu3.7","1.4.6-1ubuntu3.8","1.4.6-1ubuntu3.9","1.4.6-1ubuntu3.9+esm1","1.4.6-1ubuntu3.9+esm2","1.4.6-1ubuntu3.9+esm3","1.4.6-1ubuntu3.9+esm4","1.4.6-1ubuntu3.9+esm5"],"ecosystem_specific":{"binaries":[{"binary_name":"nginx","binary_version":"1.4.6-1ubuntu3.9+esm6"},{"binary_version":"1.4.6-1ubuntu3.9+esm6","binary_name":"nginx-common"},{"binary_name":"nginx-core","binary_version":"1.4.6-1ubuntu3.9+esm6"},{"binary_name":"nginx-extras","binary_version":"1.4.6-1ubuntu3.9+esm6"},{"binary_version":"1.4.6-1ubuntu3.9+esm6","binary_name":"nginx-full"},{"binary_name":"nginx-light","binary_version":"1.4.6-1ubuntu3.9+esm6"},{"binary_name":"nginx-naxsi","binary_version":"1.4.6-1ubuntu3.9+esm6"},{"binary_name":"nginx-naxsi-ui","binary_version":"1.4.6-1ubuntu3.9+esm6"}],"availability":"Available with Ubuntu Pro with Legacy support add-on: https://ubuntu.com/pro"},"database_specific":{"cves_map":{"cves":[{"id":"CVE-2025-53859","severity":[{"score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","type":"CVSS_V3"},{"score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N","type":"CVSS_V4"},{"score":"medium","type":"Ubuntu"}]},{"severity":[{"score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","type":"CVSS_V3"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-1642"},{"id":"CVE-2026-9256","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2026-27651","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","type":"CVSS_V3"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"},{"type":"Ubuntu","score":"medium"}]},{"severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H","type":"CVSS_V3"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H"},{"score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N","type":"CVSS_V4"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-27654"},{"id":"CVE-2026-27784","severity":[{"score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","type":"CVSS_V3"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2026-28753","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"},{"score":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N","type":"CVSS_V4"},{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2026-32647","severity":[{"score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","type":"CVSS_V4"},{"type":"Ubuntu","score":"medium"}]},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2026-40701"},{"id":"CVE-2026-42934","severity":[{"score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L","type":"CVSS_V3"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N"},{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2026-42945","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"},{"score":"high","type":"Ubuntu"}]},{"id":"CVE-2026-42946","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L"},{"score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H","type":"CVSS_V3"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N"},{"type":"Ubuntu","score":"medium"}]}],"ecosystem":"Ubuntu:Pro:14.04:LTS"},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8375-1.json"}},{"package":{"name":"nginx","ecosystem":"Ubuntu:Pro:16.04:LTS","purl":"pkg:deb/ubuntu/nginx?arch=source&distro=esm-infra-legacy%2Fxenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.10.3-0ubuntu0.16.04.5+esm7"}]}],"versions":["1.9.3-1ubuntu1","1.9.6-2ubuntu1","1.9.6-2ubuntu2","1.9.9-0ubuntu1","1.9.9-1ubuntu1","1.9.10-0ubuntu1","1.9.10-1ubuntu1","1.9.11-0ubuntu1","1.9.11-0ubuntu2","1.9.12-0ubuntu1","1.9.13-0ubuntu1","1.9.14-0ubuntu1","1.9.15-0ubuntu1","1.10.0-0ubuntu0.16.04.1","1.10.0-0ubuntu0.16.04.2","1.10.0-0ubuntu0.16.04.3","1.10.0-0ubuntu0.16.04.4","1.10.3-0ubuntu0.16.04.1","1.10.3-0ubuntu0.16.04.2","1.10.3-0ubuntu0.16.04.3","1.10.3-0ubuntu0.16.04.4","1.10.3-0ubuntu0.16.04.5","1.10.3-0ubuntu0.16.04.5+esm1","1.10.3-0ubuntu0.16.04.5+esm2","1.10.3-0ubuntu0.16.04.5+esm3","1.10.3-0ubuntu0.16.04.5+esm4","1.10.3-0ubuntu0.16.04.5+esm5","1.10.3-0ubuntu0.16.04.5+esm6"],"ecosystem_specific":{"binaries":[{"binary_name":"nginx","binary_version":"1.10.3-0ubuntu0.16.04.5+esm7"},{"binary_name":"nginx-common","binary_version":"1.10.3-0ubuntu0.16.04.5+esm7"},{"binary_name":"nginx-core","binary_version":"1.10.3-0ubuntu0.16.04.5+esm7"},{"binary_version":"1.10.3-0ubuntu0.16.04.5+esm7","binary_name":"nginx-extras"},{"binary_version":"1.10.3-0ubuntu0.16.04.5+esm7","binary_name":"nginx-full"},{"binary_version":"1.10.3-0ubuntu0.16.04.5+esm7","binary_name":"nginx-light"}],"availability":"Available with Ubuntu Pro with Legacy support add-on: https://ubuntu.com/pro"},"database_specific":{"cves_map":{"cves":[{"id":"CVE-2025-53859","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2026-1642","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"},{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2026-9256","severity":[{"score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"},{"score":"medium","type":"Ubuntu"}]},{"severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","type":"CVSS_V3"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","type":"CVSS_V4"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-27651"},{"severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H","type":"CVSS_V3"},{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H","type":"CVSS_V3"},{"score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N","type":"CVSS_V4"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-27654"},{"severity":[{"score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-27784"},{"id":"CVE-2026-28753","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"},{"type":"Ubuntu","score":"medium"}]},{"severity":[{"score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-32647"},{"id":"CVE-2026-40701","severity":[{"score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L","type":"CVSS_V3"},{"score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N","type":"CVSS_V4"},{"score":"medium","type":"Ubuntu"}]},{"severity":[{"score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L","type":"CVSS_V3"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-42934"},{"id":"CVE-2026-42945","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"score":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","type":"CVSS_V4"},{"type":"Ubuntu","score":"high"}]},{"severity":[{"score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L","type":"CVSS_V3"},{"score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H","type":"CVSS_V3"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-42946"}],"ecosystem":"Ubuntu:Pro:16.04:LTS"},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8375-1.json"}},{"package":{"name":"nginx","ecosystem":"Ubuntu:Pro:18.04:LTS","purl":"pkg:deb/ubuntu/nginx?arch=source&distro=esm-infra%2Fbionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.14.0-0ubuntu1.11+esm2"}]}],"versions":["1.12.1-0ubuntu2","1.13.6-2ubuntu1","1.13.6-2ubuntu2","1.13.10-1ubuntu1","1.13.12-0ubuntu1","1.14.0-0ubuntu1","1.14.0-0ubuntu1.1","1.14.0-0ubuntu1.2","1.14.0-0ubuntu1.3","1.14.0-0ubuntu1.4","1.14.0-0ubuntu1.5","1.14.0-0ubuntu1.6","1.14.0-0ubuntu1.7","1.14.0-0ubuntu1.9","1.14.0-0ubuntu1.10","1.14.0-0ubuntu1.11","1.14.0-0ubuntu1.11+esm1"],"ecosystem_specific":{"binaries":[{"binary_name":"libnginx-mod-http-auth-pam","binary_version":"1.14.0-0ubuntu1.11+esm2"},{"binary_name":"libnginx-mod-http-cache-purge","binary_version":"1.14.0-0ubuntu1.11+esm2"},{"binary_version":"1.14.0-0ubuntu1.11+esm2","binary_name":"libnginx-mod-http-dav-ext"},{"binary_name":"libnginx-mod-http-echo","binary_version":"1.14.0-0ubuntu1.11+esm2"},{"binary_name":"libnginx-mod-http-fancyindex","binary_version":"1.14.0-0ubuntu1.11+esm2"},{"binary_name":"libnginx-mod-http-geoip","binary_version":"1.14.0-0ubuntu1.11+esm2"},{"binary_name":"libnginx-mod-http-headers-more-filter","binary_version":"1.14.0-0ubuntu1.11+esm2"},{"binary_version":"1.14.0-0ubuntu1.11+esm2","binary_name":"libnginx-mod-http-image-filter"},{"binary_name":"libnginx-mod-http-lua","binary_version":"1.14.0-0ubuntu1.11+esm2"},{"binary_version":"1.14.0-0ubuntu1.11+esm2","binary_name":"libnginx-mod-http-ndk"},{"binary_name":"libnginx-mod-http-perl","binary_version":"1.14.0-0ubuntu1.11+esm2"},{"binary_version":"1.14.0-0ubuntu1.11+esm2","binary_name":"libnginx-mod-http-subs-filter"},{"binary_version":"1.14.0-0ubuntu1.11+esm2","binary_name":"libnginx-mod-http-uploadprogress"},{"binary_name":"libnginx-mod-http-upstream-fair","binary_version":"1.14.0-0ubuntu1.11+esm2"},{"binary_name":"libnginx-mod-http-xslt-filter","binary_version":"1.14.0-0ubuntu1.11+esm2"},{"binary_name":"libnginx-mod-mail","binary_version":"1.14.0-0ubuntu1.11+esm2"},{"binary_name":"libnginx-mod-nchan","binary_version":"1.14.0-0ubuntu1.11+esm2"},{"binary_version":"1.14.0-0ubuntu1.11+esm2","binary_name":"libnginx-mod-rtmp"},{"binary_name":"libnginx-mod-stream","binary_version":"1.14.0-0ubuntu1.11+esm2"},{"binary_version":"1.14.0-0ubuntu1.11+esm2","binary_name":"nginx"},{"binary_version":"1.14.0-0ubuntu1.11+esm2","binary_name":"nginx-common"},{"binary_version":"1.14.0-0ubuntu1.11+esm2","binary_name":"nginx-core"},{"binary_version":"1.14.0-0ubuntu1.11+esm2","binary_name":"nginx-extras"},{"binary_version":"1.14.0-0ubuntu1.11+esm2","binary_name":"nginx-full"},{"binary_version":"1.14.0-0ubuntu1.11+esm2","binary_name":"nginx-light"}],"availability":"Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro"},"database_specific":{"cves_map":{"ecosystem":"Ubuntu:Pro:18.04:LTS","cves":[{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"},{"score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N","type":"CVSS_V4"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2025-53859"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-1642"},{"id":"CVE-2026-9256","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"},{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2026-27651","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2026-27654","severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H","type":"CVSS_V3"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H"},{"score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N","type":"CVSS_V4"},{"type":"Ubuntu","score":"medium"}]},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2026-27784"},{"id":"CVE-2026-28753","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"},{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2026-32647","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","type":"CVSS_V4"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2026-40701","severity":[{"score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L","type":"CVSS_V3"},{"score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N","type":"CVSS_V4"},{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2026-42934","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L"},{"score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N","type":"CVSS_V4"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2026-42945","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"},{"type":"Ubuntu","score":"high"}]},{"id":"CVE-2026-42946","severity":[{"score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L","type":"CVSS_V3"},{"score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H","type":"CVSS_V3"},{"score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N","type":"CVSS_V4"},{"type":"Ubuntu","score":"medium"}]}]},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8375-1.json"}},{"package":{"name":"nginx","ecosystem":"Ubuntu:Pro:20.04:LTS","purl":"pkg:deb/ubuntu/nginx?arch=source&distro=esm-infra%2Ffocal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.18.0-0ubuntu1.7+esm1"}]}],"versions":["1.16.1-0ubuntu2","1.16.1-0ubuntu3","1.17.5-0ubuntu1","1.17.6-0ubuntu1","1.17.7-0ubuntu1","1.17.8-0ubuntu1","1.17.8-0ubuntu2","1.17.8-0ubuntu3","1.17.9-0ubuntu1","1.17.9-0ubuntu2","1.17.9-0ubuntu3","1.17.10-0ubuntu1","1.18.0-0ubuntu1","1.18.0-0ubuntu1.2","1.18.0-0ubuntu1.3","1.18.0-0ubuntu1.4","1.18.0-0ubuntu1.5","1.18.0-0ubuntu1.6","1.18.0-0ubuntu1.7"],"ecosystem_specific":{"availability":"Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro","binaries":[{"binary_name":"libnginx-mod-http-auth-pam","binary_version":"1.18.0-0ubuntu1.7+esm1"},{"binary_name":"libnginx-mod-http-cache-purge","binary_version":"1.18.0-0ubuntu1.7+esm1"},{"binary_name":"libnginx-mod-http-dav-ext","binary_version":"1.18.0-0ubuntu1.7+esm1"},{"binary_version":"1.18.0-0ubuntu1.7+esm1","binary_name":"libnginx-mod-http-echo"},{"binary_name":"libnginx-mod-http-fancyindex","binary_version":"1.18.0-0ubuntu1.7+esm1"},{"binary_name":"libnginx-mod-http-geoip","binary_version":"1.18.0-0ubuntu1.7+esm1"},{"binary_name":"libnginx-mod-http-geoip2","binary_version":"1.18.0-0ubuntu1.7+esm1"},{"binary_name":"libnginx-mod-http-headers-more-filter","binary_version":"1.18.0-0ubuntu1.7+esm1"},{"binary_version":"1.18.0-0ubuntu1.7+esm1","binary_name":"libnginx-mod-http-image-filter"},{"binary_version":"1.18.0-0ubuntu1.7+esm1","binary_name":"libnginx-mod-http-lua"},{"binary_name":"libnginx-mod-http-ndk","binary_version":"1.18.0-0ubuntu1.7+esm1"},{"binary_name":"libnginx-mod-http-perl","binary_version":"1.18.0-0ubuntu1.7+esm1"},{"binary_name":"libnginx-mod-http-subs-filter","binary_version":"1.18.0-0ubuntu1.7+esm1"},{"binary_name":"libnginx-mod-http-uploadprogress","binary_version":"1.18.0-0ubuntu1.7+esm1"},{"binary_name":"libnginx-mod-http-upstream-fair","binary_version":"1.18.0-0ubuntu1.7+esm1"},{"binary_version":"1.18.0-0ubuntu1.7+esm1","binary_name":"libnginx-mod-http-xslt-filter"},{"binary_name":"libnginx-mod-mail","binary_version":"1.18.0-0ubuntu1.7+esm1"},{"binary_name":"libnginx-mod-nchan","binary_version":"1.18.0-0ubuntu1.7+esm1"},{"binary_version":"1.18.0-0ubuntu1.7+esm1","binary_name":"libnginx-mod-rtmp"},{"binary_name":"libnginx-mod-stream","binary_version":"1.18.0-0ubuntu1.7+esm1"},{"binary_version":"1.18.0-0ubuntu1.7+esm1","binary_name":"nginx"},{"binary_name":"nginx-common","binary_version":"1.18.0-0ubuntu1.7+esm1"},{"binary_name":"nginx-core","binary_version":"1.18.0-0ubuntu1.7+esm1"},{"binary_version":"1.18.0-0ubuntu1.7+esm1","binary_name":"nginx-extras"},{"binary_name":"nginx-full","binary_version":"1.18.0-0ubuntu1.7+esm1"},{"binary_version":"1.18.0-0ubuntu1.7+esm1","binary_name":"nginx-light"}]},"database_specific":{"cves_map":{"ecosystem":"Ubuntu:Pro:20.04:LTS","cves":[{"id":"CVE-2025-53859","severity":[{"score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","type":"CVSS_V3"},{"score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N","type":"CVSS_V4"},{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2026-1642","severity":[{"score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","type":"CVSS_V3"},{"score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N","type":"CVSS_V4"},{"score":"medium","type":"Ubuntu"}]},{"severity":[{"score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-9256"},{"severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","type":"CVSS_V3"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","type":"CVSS_V4"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2026-27651"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H"},{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H","type":"CVSS_V3"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-27654"},{"id":"CVE-2026-27784","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"},{"type":"Ubuntu","score":"medium"}]},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-28753"},{"id":"CVE-2026-32647","severity":[{"score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2026-40701","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2026-42934","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N"},{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2026-42945","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"score":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","type":"CVSS_V4"},{"score":"high","type":"Ubuntu"}]},{"id":"CVE-2026-42946","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H"},{"score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N","type":"CVSS_V4"},{"type":"Ubuntu","score":"medium"}]}]},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8375-1.json"}}],"schema_version":"1.7.5"}