VDB
RHSA-2026%3A13634
RHSA-2026%3A13634
PUBLISHED
CVSS 7.5 HIGH
An update for nginx is now available for Red Hat Enterprise Linux 10.0 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat Enterprise Linux AppStream EUS (v. 10.0) | ||
| Red Hat Enterprise Linux CodeReady Linux Builder EUS (v. 10.0) | ||
| nginx |
Timeline
- May 5, 2026 CVE Published
- May 5, 2026 Distribution Patch
- May 5, 2026 Distribution Patch
- May 5, 2026 Security Advisory
- May 5, 2026 Security Advisory
- May 5, 2026 Security Advisory
- May 5, 2026 Security Advisory
- May 5, 2026 Security Advisory
- May 11, 2026 CVE Updated
- May 21, 2026 PoC Published
- Jun 10, 2026 PoC Published
References
- https://access.redhat.com/errata/RHSA-2026:13634 advisory
- https://access.redhat.com/security/updates/classification/#important url
- https://bugzilla.redhat.com/show_bug.cgi?id=2449598 url
- https://bugzilla.redhat.com/show_bug.cgi?id=2450776 url
- https://bugzilla.redhat.com/show_bug.cgi?id=2450785 url
- https://bugzilla.redhat.com/show_bug.cgi?id=2450791 url
- https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_13634.json advisory