-
Thu Jul 16 2026 Akshata Konala <akshata.konala@oracle.com> - 1.26.3-6.0.1.el10_2.5
- Reference oracle-indexhtml within Requires [Orabug: 33802044]
-
Fri Jul 03 2026 Luboš Uhliarik <luhliari@redhat.com> - 2:1.26.3-6.5
- Resolves: RHEL-191778 - nginx: "HTTP/2 bomb" nginx fix breaks module ABI
causing crashes
- Resolves: RHEL-188402 - nginx: NGINX: Arbitrary code execution or.
Denial of Service via heap-based buffer overflow with crafted HTTP/2
headers (CVE-2026-42055)
-
Mon Jun 08 2026 Luboš Uhliarik <luhliari@redhat.com> - 2:1.26.3-6.4
- Resolves: RHEL-178669 - nginx: code execution and denial of
service (CVE-2026-9256)
- Resolves: RHEL-182544 - nginx: HTTP/2: Remote Denial of Service via
compression bomb and Slowloris-style attack
-
Thu May 14 2026 Luboš Uhliarik <luhliari@redhat.com> - 2:1.26.3-6.3
- Resolves: RHEL-176231 - nginx: NGINX: Arbitrary Code Execution
Vulnerability (CVE-2026-42945)
-
Fri Mar 27 2026 Zdenek Dohnal <zdohnal@redhat.com> - 2:1.26.3-6.2
- rebuild for the right candidate tag
-
Thu Mar 26 2026 Zdenek Dohnal <zdohnal@redhat.com> - 2:1.26.3-6.1
- RHEL-159547 CVE-2026-27654 nginx: NGINX: Denial of Service or file modification via buffer overflow in ngx_http_dav_module
- RHEL-159526 CVE-2026-27784 nginx: NGINX: Denial of Service due to memory corruption via crafted MP4 file
- RHEL-159434 CVE-2026-27651 nginx: NGINX: Denial of Service via undisclosed requests when ngx_mail_auth_http_module is enabled
- RHEL-157875 CVE-2026-32647 nginx: NGINX: Denial of Service or Code Execution via specially crafted MP4 files
-
Wed Feb 11 2026 Luboš Uhliarik <luhliari@redhat.com> - 2:1.26.3-6
- CVE-2026-1642 nginx: NGINX: Data injection via man-in-the-middle attack
on TLS proxied connections
-
Thu Jan 29 2026 Luboš Uhliarik <luhliari@redhat.com> - 2:1.26.3-5
- Clarify binding behavior of -t option.
-
Thu Nov 20 2025 Luboš Uhliarik <luhliari@redhat.com> - 2:1.26.3-4
- Remove 50x.html from the nginx package
-
Thu Oct 23 2025 Branislav Náter <bnater@redhat.com> - 2:1.26.3-3
- Run tests in centos-stream namespace