Vulnerabilities

nginx on Linux: which version fixes what

nginx sits in front of everything and reads bytes from strangers for a living, which puts the interesting flaws in request parsing rather than in the code most people audit.

SecAI tracks 67 distinct CVEs affecting nginx across the 6 distributions below, of which 3 have no fixed package version on at least one of them. Each row names the package version that fixes it on that release.

What it is, and why it is on your server

nginx is the web server and reverse proxy in front of most modern Linux deployments, terminating TLS, serving static files, and forwarding the rest to an application behind it.

Why its advisories behave the way they do

  • Parsing is the attack surface. The dangerous advisories are in how nginx reads a request line, a header, or a chunked body, because that code runs before any of your application logic does.
  • The module set matters as much as the version. Several advisories only apply if a particular module is compiled in, and the distribution package and the nginx.org package do not ship the same set.
  • It usually runs as root to bind port 80 and 443, then drops to an unprivileged worker. The master process staying root is what makes a worker compromise worth escalating.

Check what you are actually running

The version that matters is the package version, not the upstream one. Distributions backport security fixes without changing the number before the dash, so a release that looks years old is frequently fully patched, and the revision after the dash is the only part that tells you.

Debian and Ubuntu
dpkg-query -W -f='${Package} ${Version}\n' nginx nginx-core 2>/dev/null
Rocky Linux and AlmaLinux
rpm -q nginx

Running `nginx -V` prints the modules the binary was actually built with, which is what several advisories turn on.

Fixed versions, per distribution

Each distribution patches on its own schedule and under its own version scheme, so the same CVE has a different answer on each of them. These come from the distributions’ own advisory data, asked per release. Where a release has no fixed version, that is what the advisory says, not a gap in the data.

Ubuntu 22.04 LTSsource package: nginx

CVEPublishedFixed in package version
CVE-2026-425332026-09-141.18.0-6ubuntu14.21
CVE-2026-564342026-07-161.18.0-6ubuntu14.17
CVE-2026-600052026-07-161.18.0-6ubuntu14.17
CVE-2026-420552026-06-191.18.0-6ubuntu14.16
CVE-2026-481422026-06-191.18.0-6ubuntu14.16
CVE-2026-499752026-06-031.18.0-6ubuntu14.15
CVE-2026-92562026-05-221.18.0-6ubuntu14.12
CVE-2026-429452026-05-141.18.0-6ubuntu14.11
CVE-2026-407012026-05-131.18.0-6ubuntu14.12
CVE-2026-429342026-05-131.18.0-6ubuntu14.12
CVE-2026-429462026-05-131.18.0-6ubuntu14.12
CVE-2026-276512026-03-241.18.0-6ubuntu14.10
CVE-2026-276542026-03-241.18.0-6ubuntu14.10
CVE-2026-277842026-03-241.18.0-6ubuntu14.10
CVE-2026-287532026-03-241.18.0-6ubuntu14.10
CVE-2026-326472026-03-241.18.0-6ubuntu14.10
CVE-2026-16422026-02-121.18.0-6ubuntu14.8
CVE-2025-538592025-08-251.18.0-6ubuntu14.7
CVE-2025-234192025-02-241.18.0-6ubuntu14.6
CVE-2024-73472024-09-161.18.0-6ubuntu14.5
CVE-2022-417412022-11-151.18.0-6ubuntu14.3
CVE-2022-417422022-11-151.18.0-6ubuntu14.3
CVE-2021-36182022-04-281.18.0-6ubuntu14.1

Showing the 23 most recent of 23 that apply to Ubuntu 22.04 LTS.

Ubuntu 24.04 LTSsource package: nginx

CVEPublishedFixed in package version
CVE-2026-425332026-09-141.24.0-2ubuntu7.18
CVE-2026-564342026-07-161.24.0-2ubuntu7.14
CVE-2026-600052026-07-161.24.0-2ubuntu7.14
CVE-2026-420552026-06-191.24.0-2ubuntu7.13
CVE-2026-481422026-06-191.24.0-2ubuntu7.13
CVE-2026-499752026-06-031.24.0-2ubuntu7.12
CVE-2026-92562026-05-221.24.0-2ubuntu7.9
CVE-2026-429452026-05-141.24.0-2ubuntu7.8
CVE-2026-407012026-05-131.24.0-2ubuntu7.9
CVE-2026-429342026-05-131.24.0-2ubuntu7.9
CVE-2026-429462026-05-131.24.0-2ubuntu7.9
CVE-2026-276512026-03-241.24.0-2ubuntu7.7
CVE-2026-276542026-03-241.24.0-2ubuntu7.7
CVE-2026-277842026-03-241.24.0-2ubuntu7.7
CVE-2026-287532026-03-241.24.0-2ubuntu7.7
CVE-2026-287552026-03-241.24.0-2ubuntu7.7
CVE-2026-326472026-03-241.24.0-2ubuntu7.7
CVE-2026-16422026-02-121.24.0-2ubuntu7.6
CVE-2025-538592025-08-251.24.0-2ubuntu7.5
CVE-2025-234192025-04-011.24.0-2ubuntu7.3
CVE-2024-73472024-09-161.24.0-2ubuntu7.1

Showing the 21 most recent of 21 that apply to Ubuntu 24.04 LTS.

Debian 12 (bookworm)source package: nginx

CVEPublishedFixed in package version
CVE-2026-425332026-07-151.22.1-9+deb12u10
CVE-2026-564342026-07-151.22.1-9+deb12u10
CVE-2026-600052026-07-151.22.1-9+deb12u10
CVE-2026-420552026-06-171.22.1-9+deb12u9
CVE-2026-481422026-06-171.22.1-9+deb12u9
CVE-2026-92562026-05-221.22.1-9+deb12u8
CVE-2026-407012026-05-131.22.1-9+deb12u7
CVE-2026-429342026-05-131.22.1-9+deb12u7
CVE-2026-429452026-05-131.22.1-9+deb12u7
CVE-2026-429462026-05-131.22.1-9+deb12u8
CVE-2026-276512026-03-241.22.1-9+deb12u5
CVE-2026-276542026-03-241.22.1-9+deb12u5
CVE-2026-277842026-03-241.22.1-9+deb12u5
CVE-2026-287532026-03-241.22.1-9+deb12u5
CVE-2026-326472026-03-241.22.1-9+deb12u5
CVE-2026-16422026-02-121.22.1-9+deb12u4
CVE-2025-538592025-08-131.22.1-9+deb12u3
CVE-2024-334522025-04-221.22.0-3
CVE-2025-234192025-02-051.22.1-9+deb12u1
CVE-2024-73472024-08-141.22.1-9+deb12u2
CVE-2023-444872023-10-10no fixed version released
CVE-2022-417412022-10-191.22.1-1
CVE-2022-417422022-10-191.22.1-1
CVE-2021-36182022-03-231.20.2-2
CVE-2017-200052021-06-061.13.6-1

Showing the 25 most recent of 58 that apply to Debian 12 (bookworm), 3 of which have no fixed version released.

Debian 13 (trixie)source package: nginx

CVEPublishedFixed in package version
CVE-2026-425332026-07-151.26.3-3+deb13u8
CVE-2026-564342026-07-151.26.3-3+deb13u8
CVE-2026-600052026-07-151.26.3-3+deb13u8
CVE-2026-420552026-06-171.26.3-3+deb13u7
CVE-2026-481422026-06-171.26.3-3+deb13u7
CVE-2026-92562026-05-221.26.3-3+deb13u6
CVE-2026-404602026-05-131.26.3-3+deb13u5
CVE-2026-407012026-05-131.26.3-3+deb13u5
CVE-2026-429342026-05-131.26.3-3+deb13u5
CVE-2026-429452026-05-131.26.3-3+deb13u5
CVE-2026-429462026-05-131.26.3-3+deb13u6
CVE-2026-276512026-03-241.26.3-3+deb13u3
CVE-2026-276542026-03-241.26.3-3+deb13u3
CVE-2026-277842026-03-241.26.3-3+deb13u3
CVE-2026-287532026-03-241.26.3-3+deb13u3
CVE-2026-326472026-03-241.26.3-3+deb13u3
CVE-2026-16422026-02-121.26.3-3+deb13u2
CVE-2025-538592025-08-131.26.3-3+deb13u1
CVE-2024-334522025-04-221.22.0-3
CVE-2025-234192025-02-051.26.3-2
CVE-2024-73472024-08-141.26.0-2
CVE-2024-310792024-05-291.26.0-2
CVE-2024-327602024-05-291.26.0-2
CVE-2024-341612024-05-291.26.0-2
CVE-2024-352002024-05-291.26.0-2

Showing the 25 most recent of 65 that apply to Debian 13 (trixie), 2 of which have no fixed version released.

Rocky Linux 9source package: nginx

CVEPublishedFixed in package version
CVE-2026-425332026-09-142:1.26.3-9.module+el9.8.0+40222+e48d13b6.12:1.26.3-9.module+el9.8.0+40235+8be1317a.22:1.26.3-9.module+el9.8.0+40301+37c29bcc.32:1.26.3-9.module+el9.8.0+40194+40adfc1b
CVE-2026-564342026-08-262:1.20.1-28.el9_8.5.rocky.0.1
CVE-2026-600052026-08-262:1.20.1-28.el9_8.5.rocky.0.1
CVE-2026-420552026-07-292:1.20.1-28.el9_8.4.rocky.0.1
CVE-2026-92562026-06-252:1.26.3-9.module+el9.8.0+40194+40adfc1b
CVE-2026-429452026-05-302:1.20.1-28.el9_8.2.rocky.0.1
CVE-2026-276512026-05-212:1.20.1-24.el9_7.2.rocky.0.1
CVE-2026-276542026-05-212:1.20.1-24.el9_7.2.rocky.0.1
CVE-2026-277842026-05-212:1.20.1-24.el9_7.2.rocky.0.1
CVE-2026-326472026-05-212:1.20.1-24.el9_7.2.rocky.0.1
CVE-2026-16422026-03-122:1.26.3-2.module+el9.7.0+40103+2443f6d1
CVE-2022-417412025-10-042:1.20.1-22.el9_6.2
CVE-2022-417422025-10-042:1.20.1-22.el9_6.2
CVE-2024-73472025-10-042:1.20.1-22.el9_6.2
CVE-2023-444872023-11-111:1.22.1-3.module+el9.2.0+15280+45c505d6.1

Showing the 15 most recent of 15 that apply to Rocky Linux 9.

AlmaLinux 9source package: nginx

CVEPublishedFixed in package version
CVE-2026-425332026-09-142:1.26.3-9.module_el9.8.0+309+b8a3c30d.4
CVE-2026-564342026-08-252:1.20.1-28.el9_8.5.alma.1
CVE-2026-600052026-08-252:1.20.1-28.el9_8.5.alma.1
CVE-2026-420552026-07-081:1.24.0-7.module_el9.8.0+278+b57266e8.3.alma.1
CVE-2026-92562026-06-242:1.20.1-28.el9_8.3.alma.1
CVE-2026-429452026-05-192:1.20.1-28.el9_8.2.alma.1
CVE-2026-276512026-04-092:1.26.3-2.module_el9.7.0+223+9cd7031b.1
CVE-2026-276542026-04-092:1.26.3-2.module_el9.7.0+223+9cd7031b.1
CVE-2026-277842026-04-092:1.26.3-2.module_el9.7.0+223+9cd7031b.1
CVE-2026-326472026-04-092:1.26.3-2.module_el9.7.0+223+9cd7031b.1
CVE-2026-16422026-03-242:1.20.1-24.el9_7.1.alma.1
CVE-2022-417412025-05-132:1.20.1-22.el9_6.2.alma.1
CVE-2022-417422025-05-132:1.20.1-22.el9_6.2.alma.1
CVE-2024-73472025-05-132:1.20.1-22.el9_6.2.alma.1
CVE-2023-444872023-10-251:1.22.1-3.module_el9.2.0+44+f932b372.1.alma.1

Showing the 15 most recent of 15 that apply to AlmaLinux 9.

Advisory data last refreshed 26 September 2026. It is re-read daily.

What this page does not tell you

It does not tell you whether your server is affected. A CVE applying to a package is not the same as a CVE applying to your installation: the fix may already be backported into what you are running, the vulnerable module may not be loaded, or the service may not be reachable from anywhere that matters. Answering that needs the versions on your machine, not a list.

It also carries no count of how many servers are affected. SecAI monitors a small fleet, and a percentage drawn from it would be arithmetic on a sample too small to mean anything. When that changes, the number will appear here and the page will say when it started.

Read next

Find out which of these you are running

One read-only command, no account, no agent. It reads the installed package versions on your server and tells you which advisories actually apply to them, nginx included. It changes nothing.