DSA-6496-1 nginx - security update
Checked 28 Sep 2026. BlackTree preserves the last verified facts if a later source check is temporarily unavailable.
Open the official publisher sourcePUBLISHER UPDATE · DSA-6496-1
DSA-6496-1 nginx - security update
Scope: Debian. This update record adds version, fix and known-issue context. Its publication date is not a lifecycle boundary.
Multiple vulnerabilities were discovered in nginx, a high-performance web and reverse proxy server, which may result in denial of service, memory disclosure or potentially the execution of arbitrary code. CVE-2026-42533 A heap buffer overflow was discovered in the nginx script engine. It can be triggered when a map directive performs regular expression matching and a string expression references captures modified by the map, or when non-cacheable variables change between the script length pass and the script copy pass. CVE-2026-56434 Duplicate finalization of an HTTP subrequest can result in a use-after-free. The issue is observable in configurations using server-side includes together with proxy_pass and proxy_buffering disabled, when an upstream response causes the same subrequest to be posted twice. CVE-2026-60005 ngx_http_regex_exec() could replace the captures array without clearing r->ncaptures when the new regular expression did not match. A subsequent unnamed capture could then access uninitialised memory, resulting in memory disclosure. https://security-tracker.debian.org/tracker/DSA-6496-1
Not stated. The verified publisher record does not contain a known-issues statement.
Review the official publisher document before deployment.
These links connect the publisher update to related Lifecycle records without treating the update publication date as an end-of-support date.
Checked 28 Sep 2026. BlackTree preserves the last verified facts if a later source check is temporarily unavailable.
Open the official publisher source