NGINX Open Source and NGINX Plus: Mehrere Schwachstellen
NGINX Plus ist die kommerzielle Variante von NGINX, einer Webserver-, Reverse Proxy- und E-Mail Proxy Software. NGINX ist eine Webserver-, Reverse Proxy- und E-Mail-Proxy Software.
AI Analysis
Technical Summary
This advisory covers an update to Red Hat Hardened Images RPMs, including various nginx packages (version 1.30.2-1.hum1) for architectures aarch64 and x86_64. The vulnerability CVE-2026-40460 relates to an authentication bypass issue (CWE-290). The update is intended to fix bugs and enhance the packages, though no explicit fix details or exploit information are provided. The advisory references Red Hat's official errata and security pages for further details and update instructions.
Potential Impact
The vulnerability involves an authentication bypass (CWE-290), which could potentially allow unauthorized access if exploited. However, there are no known exploits in the wild at this time. The medium severity rating suggests a moderate risk level, but the lack of detailed impact information limits precise impact assessment.
Mitigation Recommendations
Red Hat has released updated RPM packages for nginx as part of the Hardened Images update. Users should apply these updates following Red Hat's official guidance at https://images.redhat.com/. Since this is an official fix, applying the update will mitigate the vulnerability. There is no indication that additional mitigation steps are required beyond updating to the fixed packages.
NGINX Open Source and NGINX Plus: Mehrere Schwachstellen
Description
NGINX Plus ist die kommerzielle Variante von NGINX, einer Webserver-, Reverse Proxy- und E-Mail Proxy Software. NGINX ist eine Webserver-, Reverse Proxy- und E-Mail-Proxy Software.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This advisory covers an update to Red Hat Hardened Images RPMs, including various nginx packages (version 1.30.2-1.hum1) for architectures aarch64 and x86_64. The vulnerability CVE-2026-40460 relates to an authentication bypass issue (CWE-290). The update is intended to fix bugs and enhance the packages, though no explicit fix details or exploit information are provided. The advisory references Red Hat's official errata and security pages for further details and update instructions.
Potential Impact
The vulnerability involves an authentication bypass (CWE-290), which could potentially allow unauthorized access if exploited. However, there are no known exploits in the wild at this time. The medium severity rating suggests a moderate risk level, but the lack of detailed impact information limits precise impact assessment.
Mitigation Recommendations
Red Hat has released updated RPM packages for nginx as part of the Hardened Images update. Users should apply these updates following Red Hat's official guidance at https://images.redhat.com/. Since this is an official fix, applying the update will mitigate the vulnerability. There is no indication that additional mitigation steps are required beyond updating to the fixed packages.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:20351
- Cve Count
- 1
- Additional Cves
- []
- Cvss Version
- null
Threat ID: 6a160991e29bf47b50654f44
Added to database: 05/26/2026, 20:58:57 UTC
Last enriched: 05/26/2026, 22:41:33 UTC
Last updated: 07/31/2026, 19:22:58 UTC
Views: 144
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.