TencentOS Server 3: nginx:1.24 (TSSA-2026:0886)

high Nessus Plugin ID 340977

Synopsis

The remote TencentOS Server 3 host is missing one or more security updates.

Description

The version of Tencent Linux installed on the remote TencentOS Server 3 host is prior to tested version. It is, therefore, affected by multiple vulnerabilities as referenced in the TSSA-2026:0886 advisory.

Package updates are available for TencentOS Server 3 that fix the following vulnerabilities:

CVE-2026-56434:
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssi_modulemodule. This vulnerability may exist when the Server-Side Includes (SSI), proxy_pass, and proxy_buffering offdirectives are configured. With this configuration, an unauthenticated attacker with man-in-the- middle (MITM) ability to control responses from an upstream server may be able to cause a use-after-free in the NGINX worker process. This issue may lead to limited modification of memory or a restart of the NGINX worker process.

Impact:
This vulnerability may allow remote attackers to have limited control to modify memory contents or restart the NGINX worker process. There is no control plane exposure; this is a data plane issue only.

Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2026-60005:
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module. When the slicedirective and unnamed regex captures are configured or when a background cache update happens, unauthenticated attackers can send requests that may cause uninitialized memory access in the NGINX worker process, leading to limited disclosure of memory or a restart.

Impact:
This vulnerability may allow remote, unauthenticated attackers to have limited control to disclose memory contents or restart the NGINX worker process. There is no control plane exposure; this is a data plane issue only.
Note: The ngx_http_slice_modulemodule is not enabled by default; it's enabled with the --with- http_slice_moduleconfiguration parameter.

Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Tenable has extracted the preceding description block directly from the Tencent Linux security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages.

See Also

https://mirrors.tencent.com/tlinux/errata/tssa-20260886.xml

Plugin Details

Severity: High

ID: 340977

File Name: tencentos_TSSA_2026_0886.nasl

Version: 1.1

Type: Local

Published: 8/26/2026

Updated: 8/26/2026

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.5

Percentile: 96.17

CVSS v2

Risk Factor: High

Base Score: 8.5

Temporal Score: 6.3

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:C

CVSS Score Source: CVE-2026-60005

CVSS v3

Risk Factor: Medium

Base Score: 6.5

Temporal Score: 5.7

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS Score Source: CVE-2026-56434

CVSS v4

Risk Factor: High

Base Score: 8.3

Threat Score: 4.8

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N

CVSS Score Source: CVE-2026-56434

Vulnerability Information

CPE: cpe:/o:tencent:tencentos_server:3, p-cpe:/a:tencent:tencentos_server:nginx

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/etc/os-release, Host/TencentOS/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 8/24/2026

Vulnerability Publication Date: 7/15/2026

Reference Information

CVE: CVE-2026-56434, CVE-2026-60005

IAVA: 2026-A-0754