{
  "schema_version": "1.7.0",
  "id": "MGASA-2026-0301",
  "published": "2026-07-27T22:45:13Z",
  "modified": "2026-07-27T21:29:15Z",
  "summary": "Updated nginx packages fix security vulnerabilities",
  "details": "CVE-2026-42533:\nHeap buffer overflow might occur in a worker process when using the map\ndirective with regex matching if the map variable was included in a\nstring expression after a capture affected by this map; a similar issue\nmight happen when using a non-cacheable variable in a\nstring expression.\nThanks to Mufeed VH of Winfunc Research and Maxim Dounin.\n.\nCVE-2026-60005:\nUninitialized memory access might occur when using unnamed regex\ncaptures with the \"slice\" directive or background cache update, which\ncould result in worker process memory disclosure or worker process\ntermination.\n.\nCVE-2026-56434:\nUse-after-free might occur when processing a specially crafted proxied\nbackend response with the ngx_http_ssi_filter_module.\nThanks to P4P3R-HAK.\n",
  "upstream": [
    "CVE-2026-42533",
    "CVE-2026-56434",
    "CVE-2026-60005"
  ],
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://advisories.mageia.org/MGASA-2026-0301.html"
    },
    {
      "type": "REPORT",
      "url": "https://bugs.mageia.org/show_bug.cgi?id=35973"
    },
    {
      "type": "WEB",
      "url": "https://my.f5.com/manage/s/article/K000162097"
    },
    {
      "type": "WEB",
      "url": "https://my.f5.com/manage/s/article/K000162100"
    },
    {
      "type": "WEB",
      "url": "https://my.f5.com/manage/s/article/K000162098"
    },
    {
      "type": "WEB",
      "url": "https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/LIWPH3EULRVLC6TMLBZYPJ5IKQGVF6C2/"
    }
  ],
  "affected": [
    {
      "package": {
        "ecosystem": "Mageia:10",
        "name": "nginx",
        "purl": "pkg:rpm/mageia/nginx?arch=source&distro=mageia-10"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM",
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "1.30.4-1.mga10"
            }
          ]
        }
      ],
      "ecosystem_specific": {
        "section": "core"
      }
    },
    {
      "package": {
        "ecosystem": "Mageia:9",
        "name": "nginx",
        "purl": "pkg:rpm/mageia/nginx?arch=source&distro=mageia-9"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM",
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "1.30.4-1.mga9"
            }
          ]
        }
      ],
      "ecosystem_specific": {
        "section": "core"
      }
    }
  ],
  "credits": [
    {
      "name": "Mageia",
      "type": "COORDINATOR",
      "contact": [
        "https://wiki.mageia.org/en/Packages_Security_Team"
      ]
    }
  ]
}
