Echo: nginx: security update to 1.26.3-3+deb13u8

critical Tenable Self-Hosted Container Security Plugin ID 465717

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a
string expression references the map's regex capture variables before referencing the map output variable.
Alternatively, the same result could be achieved by using a non-cacheable variable in a string expression
under certain conditions. An unauthenticated attacker along with conditions beyond their control can
exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the
NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with
Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Impact: This
vulnerability may allow remote attackers to cause a denial-of-service (DoS) on the NGINX system or to
possibly trigger a code execution. There is no control plane exposure; this is a data plane issue only.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
(CVE-2026-42533)

Solution

Update the nginx library and its related packages to version 1.26.3-3+deb13u8 or later.

See Also

https://advisory.echohq.com/cve/CVE-2026-42533

Plugin Details

Severity: Critical

ID: 465717

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: High

Score: 7.9

Percentile: 99.35

CVSS v2

Risk Factor: High

Base Score: 7.6

Temporal Score: 6.3

Vector: CVSS2#AV:N/AC:H/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-42533

CVSS v3

Risk Factor: High

Base Score: 8.1

Temporal Score: 7.5

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:F/RL:O/RC:C

CVSS v4

Risk Factor: Critical

Base Score: 9.2

Threat Score: 8.2

Threat Vector: CVSS:4.0/E:P

Vector: CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 7/19/2026

Vulnerability Publication Date: 7/15/2026

Exploitable With

Core Impact

Reference Information

CVE: CVE-2026-42533

IAVA: 2026-A-0754