[USN-8038-1] nginx vulnerability

noreply+usn-bot at canonical.com noreply+usn-bot at canonical.com
Thu Feb 12 23:44:33 UTC 2026


==========================================================================
Ubuntu Security Notice USN-8038-1
February 12, 2026

nginx vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 25.10
- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS

Summary:

nginx could be made to insert content into proxied server data.

Software Description:
- nginx: small, powerful, scalable web/proxy server

Details:

It was discovered that nginx incorrectly handled proxying to upstream TLS
servers. An attacker could possibly use this issue to insert plain text
data into the response from an upstream proxied server.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 25.10
  nginx                           1.28.0-6ubuntu1.1
  nginx-core                      1.28.0-6ubuntu1.1
  nginx-extras                    1.28.0-6ubuntu1.1
  nginx-full                      1.28.0-6ubuntu1.1
  nginx-light                     1.28.0-6ubuntu1.1

Ubuntu 24.04 LTS
  nginx                           1.24.0-2ubuntu7.6
  nginx-core                      1.24.0-2ubuntu7.6
  nginx-extras                    1.24.0-2ubuntu7.6
  nginx-full                      1.24.0-2ubuntu7.6
  nginx-light                     1.24.0-2ubuntu7.6

Ubuntu 22.04 LTS
  nginx                           1.18.0-6ubuntu14.8
  nginx-core                      1.18.0-6ubuntu14.8
  nginx-extras                    1.18.0-6ubuntu14.8
  nginx-full                      1.18.0-6ubuntu14.8
  nginx-light                     1.18.0-6ubuntu14.8

In general, a standard system update will make all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-8038-1
  CVE-2026-1642

Package Information:
  https://launchpad.net/ubuntu/+source/nginx/1.28.0-6ubuntu1.1
  https://launchpad.net/ubuntu/+source/nginx/1.24.0-2ubuntu7.6
  https://launchpad.net/ubuntu/+source/nginx/1.18.0-6ubuntu14.8
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 833 bytes
Desc: OpenPGP digital signature
URL: <https://lists.ubuntu.com/archives/ubuntu-security-announce/attachments/20260212/3abea6b1/attachment.sig>


More information about the ubuntu-security-announce mailing list