{"id":"USN-8375-1","summary":"nginx vulnerabilities","details":"It was discovered that the nginx ngx_mail_smtp_module module incorrectly\nhandled certain memory operations when doing SMTP authentication. This\ncould possibly result in sensitive information being sent to the\nauthentication server. (CVE-2025-53859)\n\nIt was discovered that nginx incorrectly handled proxying to upstream TLS\nservers. An attacker could possibly use this issue to insert plain text\ndata into the response from an upstream proxied server. (CVE-2026-1642)\n\nIt was discovered that the nginx ngx_mail_auth_http_module module\nincorrectly handled certain requests. An attacker could possibly use this\nissue to cause nginx to crash, resulting in a denial of service.\n(CVE-2026-27651)\n\nIt was discovered that the nginx ngx_http_dav_module module incorrectly\nhandled certain destination URIs. An attacker could use this issue to cause\nnginx to crash, resulting in a denial of service, or possibly modify source\nor destination names outside of the document root. (CVE-2026-27654)\n\nIt was discovered that the nginx ngx_http_mp4_module module incorrectly\nhandled certain MP4 files. An attacker could use this issue to cause nginx\nto crash, resulting in a denial of service, or possibly execute arbitrary\ncode. (CVE-2026-27784, CVE-2026-32647)\n\nIt was discovered that the nginx ngx_mail_smtp_module module incorrectly\nhandled certain CRLF sequences. An attacker could possibly use this issue\nto inject arbitrary SMTP headers. (CVE-2026-28753)\n\nIt was discovered that nginx contained a use-after-free vulnerability in\nthe ngx_http_ssl_module module when client certificate verification and\nOCSP validation were enabled. A remote attacker could use this issue to\ncause nginx to crash, resulting in a denial of service, or possibly modify\ndata in memory. (CVE-2026-40701)\n\nIt was discovered that nginx did not properly handle certain proxied\nresponses in the ngx_http_charset_module module. A remote attacker could\npossibly use this issue to obtain sensitive information or cause nginx to\ncrash, resulting in a denial of service. (CVE-2026-42934)\n\nIt was discovered that the nginx ngx_http_rewrite_module component\nincorrectly handled certain rewrite directives. A remote attacker could use\nthis issue to cause nginx to crash, resulting in a denial of service, or\npossibly execute arbitrary code. (CVE-2026-42945)\n\nIt was discovered that nginx did not properly process certain SCGI and\nuWSGI responses. An attacker able to perform a machine-in-the-middle attack\ncould possibly use this issue to obtain sensitive information or cause\nnginx to crash, resulting in a denial of service. (CVE-2026-42946)\n\nIt was discovered that nginx incorrectly handled certain rewrite rules in\nthe ngx_http_rewrite_module module. A remote attacker could use this issue\nto cause nginx to crash, resulting in a denial of service, or possibly\nexecute arbitrary code. (CVE-2026-9256)","modified":"2026-06-03T18:03:10.067582292Z","published":"2026-06-03T07:11:56Z","related":["UBUNTU-CVE-2025-53859","UBUNTU-CVE-2026-1642","UBUNTU-CVE-2026-27651","UBUNTU-CVE-2026-27654","UBUNTU-CVE-2026-27784","UBUNTU-CVE-2026-28753","UBUNTU-CVE-2026-32647","UBUNTU-CVE-2026-40701","UBUNTU-CVE-2026-42934","UBUNTU-CVE-2026-42945","UBUNTU-CVE-2026-42946","UBUNTU-CVE-2026-9256"],"upstream":["CVE-2025-53859","CVE-2026-1642","CVE-2026-27651","CVE-2026-27654","CVE-2026-27784","CVE-2026-28753","CVE-2026-32647","CVE-2026-40701","CVE-2026-42934","CVE-2026-42945","CVE-2026-42946","CVE-2026-9256","UBUNTU-CVE-2025-53859","UBUNTU-CVE-2026-1642","UBUNTU-CVE-2026-27651","UBUNTU-CVE-2026-27654","UBUNTU-CVE-2026-27784","UBUNTU-CVE-2026-28753","UBUNTU-CVE-2026-32647","UBUNTU-CVE-2026-40701","UBUNTU-CVE-2026-42934","UBUNTU-CVE-2026-42945","UBUNTU-CVE-2026-42946","UBUNTU-CVE-2026-9256"],"references":[{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-8375-1"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2025-53859"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-1642"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-9256"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-27651"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-27654"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-27784"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-28753"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-32647"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-40701"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-42934"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-42945"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-42946"}],"affected":[{"package":{"name":"nginx","ecosystem":"Ubuntu:Pro:14.04:LTS","purl":"pkg:deb/ubuntu/nginx?arch=source&distro=esm-infra-legacy%2Ftrusty"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.4.6-1ubuntu3.9+esm6"}]}],"versions":["1.4.1-3ubuntu1","1.4.3-2ubuntu1","1.4.4-1ubuntu1","1.4.4-2ubuntu1","1.4.4-4ubuntu1","1.4.5-1ubuntu1","1.4.6-1ubuntu2","1.4.6-1ubuntu3","1.4.6-1ubuntu3.1","1.4.6-1ubuntu3.2","1.4.6-1ubuntu3.3","1.4.6-1ubuntu3.4","1.4.6-1ubuntu3.5","1.4.6-1ubuntu3.6","1.4.6-1ubuntu3.7","1.4.6-1ubuntu3.8","1.4.6-1ubuntu3.9","1.4.6-1ubuntu3.9+esm1","1.4.6-1ubuntu3.9+esm2","1.4.6-1ubuntu3.9+esm3","1.4.6-1ubuntu3.9+esm4","1.4.6-1ubuntu3.9+esm5"],"ecosystem_specific":{"binaries":[{"binary_name":"nginx","binary_version":"1.4.6-1ubuntu3.9+esm6"},{"binary_version":"1.4.6-1ubuntu3.9+esm6","binary_name":"nginx-common"},{"binary_version":"1.4.6-1ubuntu3.9+esm6","binary_name":"nginx-core"},{"binary_version":"1.4.6-1ubuntu3.9+esm6","binary_name":"nginx-extras"},{"binary_name":"nginx-full","binary_version":"1.4.6-1ubuntu3.9+esm6"},{"binary_version":"1.4.6-1ubuntu3.9+esm6","binary_name":"nginx-light"},{"binary_version":"1.4.6-1ubuntu3.9+esm6","binary_name":"nginx-naxsi"},{"binary_name":"nginx-naxsi-ui","binary_version":"1.4.6-1ubuntu3.9+esm6"}],"availability":"Available with Ubuntu Pro with Legacy support add-on: https://ubuntu.com/pro"},"database_specific":{"cves_map":{"cves":[{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2025-53859"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-1642"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-9256"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-27651"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-27654"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-27784"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-28753"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-32647"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-40701"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-42934"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"},{"type":"Ubuntu","score":"high"}],"id":"CVE-2026-42945"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-42946"}],"ecosystem":"Ubuntu:Pro:14.04:LTS"},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8375-1.json"}},{"package":{"name":"nginx","ecosystem":"Ubuntu:Pro:16.04:LTS","purl":"pkg:deb/ubuntu/nginx?arch=source&distro=esm-infra-legacy%2Fxenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.10.3-0ubuntu0.16.04.5+esm7"}]}],"versions":["1.9.3-1ubuntu1","1.9.6-2ubuntu1","1.9.6-2ubuntu2","1.9.9-0ubuntu1","1.9.9-1ubuntu1","1.9.10-0ubuntu1","1.9.10-1ubuntu1","1.9.11-0ubuntu1","1.9.11-0ubuntu2","1.9.12-0ubuntu1","1.9.13-0ubuntu1","1.9.14-0ubuntu1","1.9.15-0ubuntu1","1.10.0-0ubuntu0.16.04.1","1.10.0-0ubuntu0.16.04.2","1.10.0-0ubuntu0.16.04.3","1.10.0-0ubuntu0.16.04.4","1.10.3-0ubuntu0.16.04.1","1.10.3-0ubuntu0.16.04.2","1.10.3-0ubuntu0.16.04.3","1.10.3-0ubuntu0.16.04.4","1.10.3-0ubuntu0.16.04.5","1.10.3-0ubuntu0.16.04.5+esm1","1.10.3-0ubuntu0.16.04.5+esm2","1.10.3-0ubuntu0.16.04.5+esm3","1.10.3-0ubuntu0.16.04.5+esm4","1.10.3-0ubuntu0.16.04.5+esm5","1.10.3-0ubuntu0.16.04.5+esm6"],"ecosystem_specific":{"binaries":[{"binary_version":"1.10.3-0ubuntu0.16.04.5+esm7","binary_name":"nginx"},{"binary_version":"1.10.3-0ubuntu0.16.04.5+esm7","binary_name":"nginx-common"},{"binary_name":"nginx-core","binary_version":"1.10.3-0ubuntu0.16.04.5+esm7"},{"binary_version":"1.10.3-0ubuntu0.16.04.5+esm7","binary_name":"nginx-extras"},{"binary_version":"1.10.3-0ubuntu0.16.04.5+esm7","binary_name":"nginx-full"},{"binary_name":"nginx-light","binary_version":"1.10.3-0ubuntu0.16.04.5+esm7"}],"availability":"Available with Ubuntu Pro with Legacy support add-on: https://ubuntu.com/pro"},"database_specific":{"cves_map":{"cves":[{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2025-53859"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-1642"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-9256"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-27651"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-27654"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-27784"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-28753"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-32647"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-40701"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-42934"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"},{"type":"Ubuntu","score":"high"}],"id":"CVE-2026-42945"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-42946"}],"ecosystem":"Ubuntu:Pro:16.04:LTS"},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8375-1.json"}},{"package":{"name":"nginx","ecosystem":"Ubuntu:Pro:18.04:LTS","purl":"pkg:deb/ubuntu/nginx?arch=source&distro=esm-infra%2Fbionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.14.0-0ubuntu1.11+esm2"}]}],"versions":["1.12.1-0ubuntu2","1.13.6-2ubuntu1","1.13.6-2ubuntu2","1.13.10-1ubuntu1","1.13.12-0ubuntu1","1.14.0-0ubuntu1","1.14.0-0ubuntu1.1","1.14.0-0ubuntu1.2","1.14.0-0ubuntu1.3","1.14.0-0ubuntu1.4","1.14.0-0ubuntu1.5","1.14.0-0ubuntu1.6","1.14.0-0ubuntu1.7","1.14.0-0ubuntu1.9","1.14.0-0ubuntu1.10","1.14.0-0ubuntu1.11","1.14.0-0ubuntu1.11+esm1"],"ecosystem_specific":{"binaries":[{"binary_version":"1.14.0-0ubuntu1.11+esm2","binary_name":"libnginx-mod-http-auth-pam"},{"binary_name":"libnginx-mod-http-cache-purge","binary_version":"1.14.0-0ubuntu1.11+esm2"},{"binary_version":"1.14.0-0ubuntu1.11+esm2","binary_name":"libnginx-mod-http-dav-ext"},{"binary_version":"1.14.0-0ubuntu1.11+esm2","binary_name":"libnginx-mod-http-echo"},{"binary_version":"1.14.0-0ubuntu1.11+esm2","binary_name":"libnginx-mod-http-fancyindex"},{"binary_version":"1.14.0-0ubuntu1.11+esm2","binary_name":"libnginx-mod-http-geoip"},{"binary_version":"1.14.0-0ubuntu1.11+esm2","binary_name":"libnginx-mod-http-headers-more-filter"},{"binary_version":"1.14.0-0ubuntu1.11+esm2","binary_name":"libnginx-mod-http-image-filter"},{"binary_version":"1.14.0-0ubuntu1.11+esm2","binary_name":"libnginx-mod-http-lua"},{"binary_version":"1.14.0-0ubuntu1.11+esm2","binary_name":"libnginx-mod-http-ndk"},{"binary_version":"1.14.0-0ubuntu1.11+esm2","binary_name":"libnginx-mod-http-perl"},{"binary_version":"1.14.0-0ubuntu1.11+esm2","binary_name":"libnginx-mod-http-subs-filter"},{"binary_version":"1.14.0-0ubuntu1.11+esm2","binary_name":"libnginx-mod-http-uploadprogress"},{"binary_version":"1.14.0-0ubuntu1.11+esm2","binary_name":"libnginx-mod-http-upstream-fair"},{"binary_version":"1.14.0-0ubuntu1.11+esm2","binary_name":"libnginx-mod-http-xslt-filter"},{"binary_version":"1.14.0-0ubuntu1.11+esm2","binary_name":"libnginx-mod-mail"},{"binary_name":"libnginx-mod-nchan","binary_version":"1.14.0-0ubuntu1.11+esm2"},{"binary_name":"libnginx-mod-rtmp","binary_version":"1.14.0-0ubuntu1.11+esm2"},{"binary_version":"1.14.0-0ubuntu1.11+esm2","binary_name":"libnginx-mod-stream"},{"binary_version":"1.14.0-0ubuntu1.11+esm2","binary_name":"nginx"},{"binary_name":"nginx-common","binary_version":"1.14.0-0ubuntu1.11+esm2"},{"binary_name":"nginx-core","binary_version":"1.14.0-0ubuntu1.11+esm2"},{"binary_name":"nginx-extras","binary_version":"1.14.0-0ubuntu1.11+esm2"},{"binary_name":"nginx-full","binary_version":"1.14.0-0ubuntu1.11+esm2"},{"binary_version":"1.14.0-0ubuntu1.11+esm2","binary_name":"nginx-light"}],"availability":"Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro"},"database_specific":{"cves_map":{"cves":[{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2025-53859"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-1642"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-9256"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-27651"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-27654"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-27784"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-28753"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-32647"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-40701"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-42934"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"},{"type":"Ubuntu","score":"high"}],"id":"CVE-2026-42945"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-42946"}],"ecosystem":"Ubuntu:Pro:18.04:LTS"},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8375-1.json"}},{"package":{"name":"nginx","ecosystem":"Ubuntu:Pro:20.04:LTS","purl":"pkg:deb/ubuntu/nginx?arch=source&distro=esm-infra%2Ffocal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.18.0-0ubuntu1.7+esm1"}]}],"versions":["1.16.1-0ubuntu2","1.16.1-0ubuntu3","1.17.5-0ubuntu1","1.17.6-0ubuntu1","1.17.7-0ubuntu1","1.17.8-0ubuntu1","1.17.8-0ubuntu2","1.17.8-0ubuntu3","1.17.9-0ubuntu1","1.17.9-0ubuntu2","1.17.9-0ubuntu3","1.17.10-0ubuntu1","1.18.0-0ubuntu1","1.18.0-0ubuntu1.2","1.18.0-0ubuntu1.3","1.18.0-0ubuntu1.4","1.18.0-0ubuntu1.5","1.18.0-0ubuntu1.6","1.18.0-0ubuntu1.7"],"ecosystem_specific":{"binaries":[{"binary_name":"libnginx-mod-http-auth-pam","binary_version":"1.18.0-0ubuntu1.7+esm1"},{"binary_version":"1.18.0-0ubuntu1.7+esm1","binary_name":"libnginx-mod-http-cache-purge"},{"binary_name":"libnginx-mod-http-dav-ext","binary_version":"1.18.0-0ubuntu1.7+esm1"},{"binary_version":"1.18.0-0ubuntu1.7+esm1","binary_name":"libnginx-mod-http-echo"},{"binary_name":"libnginx-mod-http-fancyindex","binary_version":"1.18.0-0ubuntu1.7+esm1"},{"binary_version":"1.18.0-0ubuntu1.7+esm1","binary_name":"libnginx-mod-http-geoip"},{"binary_version":"1.18.0-0ubuntu1.7+esm1","binary_name":"libnginx-mod-http-geoip2"},{"binary_version":"1.18.0-0ubuntu1.7+esm1","binary_name":"libnginx-mod-http-headers-more-filter"},{"binary_version":"1.18.0-0ubuntu1.7+esm1","binary_name":"libnginx-mod-http-image-filter"},{"binary_name":"libnginx-mod-http-lua","binary_version":"1.18.0-0ubuntu1.7+esm1"},{"binary_version":"1.18.0-0ubuntu1.7+esm1","binary_name":"libnginx-mod-http-ndk"},{"binary_version":"1.18.0-0ubuntu1.7+esm1","binary_name":"libnginx-mod-http-perl"},{"binary_version":"1.18.0-0ubuntu1.7+esm1","binary_name":"libnginx-mod-http-subs-filter"},{"binary_version":"1.18.0-0ubuntu1.7+esm1","binary_name":"libnginx-mod-http-uploadprogress"},{"binary_name":"libnginx-mod-http-upstream-fair","binary_version":"1.18.0-0ubuntu1.7+esm1"},{"binary_version":"1.18.0-0ubuntu1.7+esm1","binary_name":"libnginx-mod-http-xslt-filter"},{"binary_version":"1.18.0-0ubuntu1.7+esm1","binary_name":"libnginx-mod-mail"},{"binary_version":"1.18.0-0ubuntu1.7+esm1","binary_name":"libnginx-mod-nchan"},{"binary_version":"1.18.0-0ubuntu1.7+esm1","binary_name":"libnginx-mod-rtmp"},{"binary_name":"libnginx-mod-stream","binary_version":"1.18.0-0ubuntu1.7+esm1"},{"binary_version":"1.18.0-0ubuntu1.7+esm1","binary_name":"nginx"},{"binary_name":"nginx-common","binary_version":"1.18.0-0ubuntu1.7+esm1"},{"binary_name":"nginx-core","binary_version":"1.18.0-0ubuntu1.7+esm1"},{"binary_version":"1.18.0-0ubuntu1.7+esm1","binary_name":"nginx-extras"},{"binary_version":"1.18.0-0ubuntu1.7+esm1","binary_name":"nginx-full"},{"binary_name":"nginx-light","binary_version":"1.18.0-0ubuntu1.7+esm1"}],"availability":"Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro"},"database_specific":{"cves_map":{"cves":[{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2025-53859"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-1642"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-9256"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-27651"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-27654"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-27784"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-28753"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-32647"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-40701"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-42934"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"},{"type":"Ubuntu","score":"high"}],"id":"CVE-2026-42945"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-42946"}],"ecosystem":"Ubuntu:Pro:20.04:LTS"},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8375-1.json"}}],"schema_version":"1.7.5"}