Echo: nginx: security update to 1.26.3-3+deb13u7+e1

high Tenable Cloud Security Plugin ID 463588

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_dav_module module that might allow
an attacker to trigger a buffer overflow to the NGINX worker process; this vulnerability may result in
termination of the NGINX worker process or modification of source or destination file names outside the
document root. This issue affects NGINX Open Source and NGINX Plus when the configuration file uses DAV
module MOVE or COPY methods, prefix location (nonregular expression location configuration), and alias
directives. The integrity impact is constrained because the NGINX worker process user has low privileges
and does not have access to the entire system. Note: Software versions which have reached End of Technical
Support (EoTS) are not evaluated. (CVE-2026-27654)

Solution

Update the nginx library and its related packages to version 1.26.3-3+deb13u7+e1 or later.

See Also

https://access.redhat.com/errata/RHSA-2026:10065

https://access.redhat.com/errata/RHSA-2026:13634

https://access.redhat.com/errata/RHSA-2026:13680

https://access.redhat.com/errata/RHSA-2026:13839

https://access.redhat.com/errata/RHSA-2026:14836

https://access.redhat.com/errata/RHSA-2026:15942

https://access.redhat.com/errata/RHSA-2026:15943

https://access.redhat.com/errata/RHSA-2026:15945

https://access.redhat.com/errata/RHSA-2026:15966

https://access.redhat.com/errata/RHSA-2026:6906

https://access.redhat.com/errata/RHSA-2026:6907

https://access.redhat.com/errata/RHSA-2026:6923

https://access.redhat.com/errata/RHSA-2026:7002

https://access.redhat.com/errata/RHSA-2026:7343

https://access.redhat.com/errata/RHSA-2026:8346

https://advisory.echohq.com/cve/CVE-2026-27654

Plugin Details

Severity: High

ID: 463588

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Medium

Score: 5.5

Percentile: 95.9

CVSS v2

Risk Factor: High

Base Score: 8.5

Temporal Score: 6.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:C

CVSS Score Source: CVE-2026-27654

CVSS v3

Risk Factor: High

Base Score: 8.2

Temporal Score: 7.4

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

CVSS v4

Risk Factor: High

Base Score: 8.8

Threat Score: 7.8

Threat Vector: CVSS:4.0/E:P

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 7/20/2026

Vulnerability Publication Date: 3/24/2026

Reference Information

CVE: CVE-2026-27654