Alpine: nginx: security update to 1.30.4-r0

critical Tenable Self-Hosted Container Security Plugin ID 444867

Description

There are packages installed that are affected by multiple vulnerabilities referenced in the following CVEs:

- A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a
string expression references the map's regex capture variables before referencing the map output variable.
Alternatively, the same result could be achieved by using a non-cacheable variable in a string expression
under certain conditions. An unauthenticated attacker along with conditions beyond their control can
exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the
NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with
Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Impact: This
vulnerability may allow remote attackers to cause a denial-of-service (DoS) on the NGINX system or to
possibly trigger a code execution. There is no control plane exposure; this is a data plane issue only.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
(CVE-2026-42533)

- NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssi_module module. This
vulnerability may exist when the Server-Side Includes (SSI), proxy_pass, and proxy_buffering off
directives are configured. With this configuration, an unauthenticated attacker with man-in-the-middle
(MITM) ability to control responses from an upstream server may be able to cause a use-after-free in the
NGINX worker process. This issue may lead to limited modification of memory or a restart of the NGINX
worker process. Impact: This vulnerability may allow remote attackers to have limited control to modify
memory contents or restart the NGINX worker process. There is no control plane exposure; this is a data
plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not
evaluated. (CVE-2026-56434)

- NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module. When the slice
directive and unnamed regex captures are configured or when a background cache update happens,
unauthenticated attackers can send requests that may cause uninitialized memory access in the NGINX worker
process, leading to limited disclosure of memory or a restart. Impact: This vulnerability may allow
remote, unauthenticated attackers to have limited control to disclose memory contents or restart the NGINX
worker process. There is no control plane exposure; this is a data plane issue only. Note: The
ngx_http_slice_module module is not enabled by default; it's enabled with the --with-http_slice_module
configuration parameter. Note: Software versions which have reached End of Technical Support (EoTS) are
not evaluated. (CVE-2026-60005)

Solution

Update the nginx library and its related packages to version 1.30.4-r0 or later.

See Also

https://security.alpinelinux.org/vuln/CVE-2026-42533

https://security.alpinelinux.org/vuln/CVE-2026-56434

https://security.alpinelinux.org/vuln/CVE-2026-60005

Plugin Details

Severity: Critical

ID: 444867

Version: Revision 1.1

Type: Local

Published: 7/20/2026

Updated: 7/20/2026

Supported Sensors: Agentless Assessment

Risk Information

VPR

Risk Factor: High

Score: 7.7

Percentile: 99.05

CVSS v2

Risk Factor: High

Base Score: 8.5

Temporal Score: 6.3

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:C

CVSS Score Source: CVE-2026-60005

CVSS v3

Risk Factor: High

Base Score: 8.1

Temporal Score: 7.1

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS Score Source: CVE-2026-42533

CVSS v4

Risk Factor: Critical

Base Score: 9.2

Threat Score: 7.2

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

CVSS Score Source: CVE-2026-42533

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 7/15/2026

Reference Information

CVE: CVE-2026-42533, CVE-2026-56434, CVE-2026-60005