#1140361 nginx: CVE-2026-48142

Package:
src:nginx
Source:
src:nginx
Submitter:
Salvatore Bonaccorso
Date:
2026-07-18 16:15:02 UTC
Severity:
normal
Tags:
#1140361#5
Date:
2026-06-19 03:51:12 UTC
From:
To:
Hi,

The following vulnerability was published for nginx.

CVE-2026-48142[0]:
| NGINX Plus and NGINX Open Source have a vulnerability in the
| ngx_http_charset_module module. When content is served or proxied
| through a location block with both source_charset utf-8; and a
| charset directive (for example, charset koi8-r;) configured, remote,
| unauthenticated attackers can send requests (in conjunction with
| conditions beyond their control) to cause a heap buffer over-read in
| the NGINX worker process, leading to limited disclosure of memory or
| a restart.    Note: Software versions which have reached End of
| Technical Support (EoTS) are not evaluated.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-48142
https://www.cve.org/CVERecord?id=CVE-2026-48142
[1] https://my.f5.com/manage/s/article/K000161585
[2] https://github.com/nginx/nginx/commit/60c4243eb8775d51662a01def8a7dad5d9fb34a7

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1140361#10
Date:
2026-06-24 20:35:50 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
nginx, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1140361@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Jan Mojžíš <janmojzis@debian.org> (supplier of updated nginx package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Wed, 24 Jun 2026 19:29:57 +0000
Source: nginx
Architecture: source
Version: 1.30.1-6
Distribution: unstable
Urgency: medium
Maintainer: Debian Nginx Maintainers <pkg-nginx-maintainers@alioth-lists.debian.net>
Changed-By: Jan Mojžíš <janmojzis@debian.org>
Closes: 1124757 1140361 1140605
Changes:
 nginx (1.30.1-6) unstable; urgency=medium
 .
   * d/p/fix-cache-line-size-for-loongarch64.patch add,
     backport loongarch64 detection and set cache line size 64
     (Closes: 1140605)
   * d/control: add `Suggests logrotate` for nginx-common (Closes: 1124757)
   * d/changelog: fix the 1.30.1-5 entry, which already closed bug #1140361
     (Closes: 1140361)
Checksums-Sha1:
 379867e41016146fc6d9f4e5e7ec4e0ca835df84 3803 nginx_1.30.1-6.dsc
 c587557aa93c83009f036a6c2eef0d50e78781e5 78572 nginx_1.30.1-6.debian.tar.xz
 f70703dc045d411a4825c663d52e256f07def524 3121372 nginx_1.30.1-6.git.tar.xz
 b2807788f9ff57c3c3f922147c89d66f116c906f 17484 nginx_1.30.1-6_source.buildinfo
Checksums-Sha256:
 cf842aefd9ac755c25fe6976cd329922c749b8daa747cf3a78e809805ca71180 3803 nginx_1.30.1-6.dsc
 e6b592a38c1dc3358e9230b6ec912d4663e12234ff951cb764531cb788dda69c 78572 nginx_1.30.1-6.debian.tar.xz
 2f43ef3dea7f9f44ad853b095c1a7dec134a98e1c9c77ac8b8489357e60debdb 3121372 nginx_1.30.1-6.git.tar.xz
 933b011b6624b3d2135b167da7c8b6e44c43f73c53d97ec4b279d2111fb9e914 17484 nginx_1.30.1-6_source.buildinfo
Files:
 f29a6e17511ce7b111af09808b14ba4f 3803 httpd optional nginx_1.30.1-6.dsc
 f9f2c90464a04d4caee0eee5dcf54b8f 78572 httpd optional nginx_1.30.1-6.debian.tar.xz
 fb0ccd397b78b542d12fac667c165634 3121372 httpd None nginx_1.30.1-6.git.tar.xz
 bafa2c7c338723bf5ebe39f5f815554b 17484 httpd optional nginx_1.30.1-6_source.buildinfo
Git-Tag-Info: tag=8f13e9810e558ec9b570bf61f59886ed4b11929f fp=d008b0c23d8479e46b9fcb9045da517496939ff9
Git-Tag-Tagger: Jan Mojžíš <jan.mojzis@gmail.com>
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEN02M5NuW6cvUwJcqYG0ITkaDwHkFAmo8NGYACgkQYG0ITkaD
wHlefRAAsRnfmYE05aUQSrtYrdy9EGxewjpRc4EFV+NovhVCiufygAzmEdm7yclL
hdABCAxdY5dO5Ob4fx2dOAR3VKwy0qrBKiSw5jSoVahD/LFUDvGii869QbKZaxuI
39/QI1/G1eaVjk4rBeQN1yz6of+HasK7B74IycKY9IqxyOq3wegsoxC0hNz5YVF9
CXaBLrLkFuq12mHXvkW2fmLMoFmXMKVSYTg9wBvCVn1iQs5HlK+Rd0jZisu118QO
9rR7ksUte8l0hkNE3lYppTO+V3gegMtU00JRZhP9MAe5qGZdNLnnAfOIINapzupm
iXjin67uo460vbe012GKFb77c0LRQtuoRNdGW0aXLgKGa28CqJcTnPVrhMDpUelI
nsVAJk/EqpDUjkfzrhhVtoZc0cont42mLd+11Onn2S71WXrYuil14nstYPSqm5fO
zSXX4+12vrwEhjjMkEfWqSdUksIWWp1Lacalym1T3ni1/XwGMQaf3+DFxvR4HUIW
s6pSoa4qGNmvwjPrWdAApSZNRTQqIJHsTIlDl75Ak8/lJKPySTZt/pbXpfyRmp+9
fcxNu7/CESV4YJESRSyyBYW821SEv2JLM+QUM4P+9owT5PmcgKM3R+W0tuaB9kQ8
sy0NRmy3jkfgJToN58WAnAyFz/8tD8Kuda5nwv5qR8ZEVMw4S0k=
=R91o
-----END PGP SIGNATURE-----

#1140361#13
Date:
2026-07-01 10:52:42 UTC
From:
To:
Hello,

Bug #1140361 in nginx reported by you has been fixed in the Git repository.
You can see the commit message below and you can check the diff of the fix at:

https://salsa.debian.org/nginx-team/nginx/-/commit/7d5fb1ed6f5e5e0cca341e70b5a513fdedce714d

Closes: #1140361
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1140361

#1140361#18
Date:
2026-07-04 10:02:51 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
nginx, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1140361@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Salvatore Bonaccorso <carnil@debian.org> (supplier of updated nginx package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Sat, 27 Jun 2026 22:33:06 +0200
Source: nginx
Architecture: source
Version: 1.26.3-3+deb13u7
Distribution: trixie-security
Urgency: high
Maintainer: Debian Nginx Maintainers <pkg-nginx-maintainers@alioth-lists.debian.net>
Changed-By: Salvatore Bonaccorso <carnil@debian.org>
Closes: 1140359 1140361
Changes:
 nginx (1.26.3-3+deb13u7) trixie-security; urgency=high
 .
   * Non-maintainer upload by the Security Team.
   * Upstream: limit header length for HTTP/2 and gRPC (CVE-2026-42055)
     (Closes: #1140359)
   * Charset: fixed another rare buffer overread in recode_from_utf8()
     (CVE-2026-48142) (Closes: #1140361)
Checksums-Sha1:
 88d2932f85883790729500395b595ee754c342b3 3953 nginx_1.26.3-3+deb13u7.dsc
 3d91dada31ac9fee539f1ddfbef14084319df5cb 92748 nginx_1.26.3-3+deb13u7.debian.tar.xz
 f449aab4057bbf1e25e24370f37c0dcc26febf77 6308 nginx_1.26.3-3+deb13u7_source.buildinfo
Checksums-Sha256:
 12ea342366d81030e59e3a0ac9591ca549f5da023d85055f0a25d99e68378381 3953 nginx_1.26.3-3+deb13u7.dsc
 19fcf637728c01356f4c80909812b32bc38d6f10eabc1e7fa2bb2c6fbcf27474 92748 nginx_1.26.3-3+deb13u7.debian.tar.xz
 e99e0c54070ead7a45891e72c02da52622aa924b546c8f51d3da640a5b390dc1 6308 nginx_1.26.3-3+deb13u7_source.buildinfo
Files:
 6df53f7005030c662573cc9fd5b3b178 3953 httpd optional nginx_1.26.3-3+deb13u7.dsc
 17694b7c9829210f1401ed3471e95d5e 92748 httpd optional nginx_1.26.3-3+deb13u7.debian.tar.xz
 4c57def4cc45df1daa22ac88f04926ec 6308 httpd optional nginx_1.26.3-3+deb13u7_source.buildinfo
-----BEGIN PGP SIGNATURE-----

iQKmBAEBCgCQFiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmpBhzxfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2
NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQSHGNhcm5pbEBk
ZWJpYW4ub3JnAAoJEAVMuPMTQ89EbgsP/2Posd1cuhRcPHG6J0ElVbi3VsCY1muG
woOR6qR5Ru3DrVujRiGVu0GRAO2k0fwCIRzdVBOaxDzZoi75/1jHLJ3CByd19JKq
2mZ+qzrcIfpX2UyuBUfIu+ziRJXIaxMyNNaWXA4AB+owA/6VZjILGcyhHMFD0Jy5
SkAZ09A6Nginxkzixp5Lx+NWSALZvOaQ0UFl7x262E4z3dpCMWSOUu+uiOL45U+Q
OOVAf4z7mblLKLM7kaTOAPJBnw3zM4ewhKVtcttct/NHC52NhCz/VrXu1f0gs1PF
hWyQV/oj9Gs85t2s9Cf7xA8qvGdsWjwgz5xYqBY5yy5GEEio9klzFWZFtrUh/xWW
NsS9+K0SxVwaLRO8a5slNrlDuFQB1UPk8B/um1HHRozoPzVYdNA1ByKW+ldvsve9
KOiE9zXgOq29I9Vdw7e3CQv1SfZquAhRv87CwARaIEz4YBYWFbyjFtnKUVseVKzf
OOhS2DOzVSSi70id8+Q0MXJQyesk57WZ7c+feJvpWF2B9Wnn3pMEkh8XsOqz1ZUb
9qduarfjZPhpHS7s4OcC+XzMU0ESAqcLG99WSNyxVfaBw+fdI5FvGham3WEzR6hE
B++Bdt6+P/tF5+fP2C7vkrkLwgLns+Zn5rG8B2CTDbgcCoIjUrxcUqAsREPLRIkm
p9yMtGeN3vgt
=BSjN
-----END PGP SIGNATURE-----

#1140361#23
Date:
2026-07-04 10:32:25 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
nginx, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1140361@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Carlos Henrique Lima Melara <charlesmelara@riseup.net> (supplier of updated nginx package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Tue, 30 Jun 2026 22:05:01 -0300
Source: nginx
Architecture: source
Version: 1.22.1-9+deb12u9
Distribution: bookworm-security
Urgency: medium
Maintainer: Debian Nginx Maintainers <pkg-nginx-maintainers@alioth-lists.debian.net>
Changed-By: Carlos Henrique Lima Melara <charlesmelara@riseup.net>
Closes: 1140359 1140361
Changes:
 nginx (1.22.1-9+deb12u9) bookworm-security; urgency=medium
 .
   * Non-maintainer upload by the LTS Team.
   * debian/gbp.conf: set debian-branch to debian/bookworm.
   * debian/patches: import upstream patches to fix vulnerabilities.
       - CVE-2026-42055.patch: backport from upstream; (Closes: #1140359)
       - CVE-2026-48142.patch: cherry-pick from upstream. (Closes: #1140361)
   * debian/tests/abicheck: cherry-pick from debain/trixie, remove chown, add
     warn when it fails and remove needs-root restriction.
Checksums-Sha1:
 d3f4e6721c4f3a852fa0a604bc75900dfe87d408 3594 nginx_1.22.1-9+deb12u9.dsc
 45a89797f7c789287c7f663811efbbd19e84f154 1073948 nginx_1.22.1.orig.tar.gz
 7f9c8b261edecb645f4c0a835f7422f2486cee42 86524 nginx_1.22.1-9+deb12u9.debian.tar.xz
 e82648b4b875593d65570b2d01d50baed342e986 6049 nginx_1.22.1-9+deb12u9_source.buildinfo
Checksums-Sha256:
 28baa4abda06503ae8ecde6e9f049905de7c172d6ec767636628bfcd87499cf4 3594 nginx_1.22.1-9+deb12u9.dsc
 9ebb333a9e82b952acd3e2b4aeb1d4ff6406f72491bab6cd9fe69f0dea737f31 1073948 nginx_1.22.1.orig.tar.gz
 3aebca44037e31b4148cec5a10dc673fdac176411aaa65a0094135895d154223 86524 nginx_1.22.1-9+deb12u9.debian.tar.xz
 7552e7d6aa39cdd6d5d4dfec8533d3670a50330ec1b6a18f23b26e7ee41915cf 6049 nginx_1.22.1-9+deb12u9_source.buildinfo
Files:
 ef6570185853d8af66df580ff40760d5 3594 httpd optional nginx_1.22.1-9+deb12u9.dsc
 8296d957561aeed0261d9be4d3decaec 1073948 httpd optional nginx_1.22.1.orig.tar.gz
 4b5846cc93e3081f11259b9dfa3aa12e 86524 httpd optional nginx_1.22.1-9+deb12u9.debian.tar.xz
 7f5d9ff00943baf3ad0e17930d7ec008 6049 httpd optional nginx_1.22.1-9+deb12u9_source.buildinfo
-----BEGIN PGP SIGNATURE-----

iQJNBAEBCgA3FiEECgzx8d8+AINglLHJt4M9ggJ8mQsFAmpH5z4ZHGNoYXJsZXNt
ZWxhcmFAcmlzZXVwLm5ldAAKCRC3gz2CAnyZC61iD/kB74h3E0bZ35vjjuLI5LmI
/FYTJlAJoRaUBvHi7tPKWLIm82/pGX6nB4wJ6/vUgiByCtYIHCLsch1cjLl05nt2
F0Ye2RCGng5DqoFTkGcWhKFHvrstZ4it+Rxb8vAOPYtxw4luLhUqW6VEMuzdicS0
+7lVDCRbE+wF6P5xAup7NO6wNlkJkTwOaTZHmF/wPzmuYj8oTsBACr2be1RdMMVo
PIGqXuj31qMLviEn0dnmnlgYng7W9UHEI6KaJfHepr+UAjpIwEhg7qxAT7lqqJCo
hOMrEudmoLUcUHj8/HtMZHYHWoP5HNVQj4RqmXf6a/X8hIjRcv44qYh1cqEaSysJ
6+gDJW19l8W45t8RJGv+7d93dp/wFvPpw+rEQsTx+YORntTMrmTj5VXBiyZe84wq
HxiTUyWi+ZP1t549MENZfuvAvwmvDGshkFu5e6QM7KGFiifXZf7SKRr0+GBdMWTO
PaFAUmOIdVd/mhrFEXzA8xL/HLaiOwwRRTbKJHiklnq03K+z+2kj2FtAYr+1fg8N
SCBc5L6STPLh9D1Ro9ByW7Eq+3r+Hlh2PLxZ8D+uS1+YVBnkvdFb1Z+lbv85fjsV
W0oPEmBft70zJDm5UkSkOcRclNX3nDx+VUUSMjow97mQfsCk44Z/mjqErHxdoEek
UeFMtuJq+99V8Y+bPu6pVQ==
=dPEl
-----END PGP SIGNATURE-----

#1140361#24
Date:
2026-07-07 18:19:37 UTC
From:
To:
Hello,

Bug #1140361 in nginx reported by you has been fixed in the Git repository.
You can see the commit message below and you can check the diff of the fix at:

https://salsa.debian.org/nginx-team/nginx/-/commit/37297a5094f0d6c560fb5a259f4d7bda543518dd
------------------------------------------------------------------------ Import Debian changes 1.18.0-6.1+deb11u8 nginx (1.18.0-6.1+deb11u8) bullseye-security; urgency=medium . * Non-maintainer upload by the LTS Team. * debian/gbp.conf: set debian-branch to debian/bullseye. * debian/patches: import upstream patches to fix vulnerabilities. - CVE-2026-42055.patch: backport from upstream; (Closes: #1140359) - CVE-2026-48142.patch: cherry-pick from upstream; (Closes: #1140361) - FIX-HTTP2bomb.patch: backport from upstream. (Closes: #1138794) . nginx (1.18.0-6.1+deb11u7) bullseye-security; urgency=medium . * Non-maintainer upload by the LTS Team. * debian/patches/CVE-2026-9256.patch: cherry-pick from upstream. (Closes: #1137339) ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1140361
#1140361#25
Date:
2026-07-07 19:02:35 UTC
From:
To:
Hello,

Bug #1140361 in nginx reported by you has been fixed in the Git repository.
You can see the commit message below and you can check the diff of the fix at:

https://salsa.debian.org/nginx-team/nginx/-/commit/37297a5094f0d6c560fb5a259f4d7bda543518dd
------------------------------------------------------------------------ Import Debian changes 1.18.0-6.1+deb11u8 nginx (1.18.0-6.1+deb11u8) bullseye-security; urgency=medium . * Non-maintainer upload by the LTS Team. * debian/gbp.conf: set debian-branch to debian/bullseye. * debian/patches: import upstream patches to fix vulnerabilities. - CVE-2026-42055.patch: backport from upstream; (Closes: #1140359) - CVE-2026-48142.patch: cherry-pick from upstream; (Closes: #1140361) - FIX-HTTP2bomb.patch: backport from upstream. (Closes: #1138794) . nginx (1.18.0-6.1+deb11u7) bullseye-security; urgency=medium . * Non-maintainer upload by the LTS Team. * debian/patches/CVE-2026-9256.patch: cherry-pick from upstream. (Closes: #1137339) ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1140361
#1140361#26
Date:
2026-07-08 01:35:49 UTC
From:
To:
Hello,

Bug #1140361 in nginx reported by you has been fixed in the Git repository.
You can see the commit message below and you can check the diff of the fix at:

https://salsa.debian.org/nginx-team/nginx/-/commit/2004a82149c5344b8b29d8a3c551c0a411ca8c27
------------------------------------------------------------------------ Import Debian changes 1.26.3-3+deb13u7 nginx (1.26.3-3+deb13u7) trixie-security; urgency=high . * Non-maintainer upload by the Security Team. * Upstream: limit header length for HTTP/2 and gRPC (CVE-2026-42055) (Closes: #1140359) * Charset: fixed another rare buffer overread in recode_from_utf8() (CVE-2026-48142) (Closes: #1140361) ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1140361
#1140361#27
Date:
2026-07-08 01:39:24 UTC
From:
To:
Hello,

Bug #1140361 in nginx reported by you has been fixed in the Git repository.
You can see the commit message below and you can check the diff of the fix at:

https://salsa.debian.org/nginx-team/nginx/-/commit/2004a82149c5344b8b29d8a3c551c0a411ca8c27
------------------------------------------------------------------------ Import Debian changes 1.26.3-3+deb13u7 nginx (1.26.3-3+deb13u7) trixie-security; urgency=high . * Non-maintainer upload by the Security Team. * Upstream: limit header length for HTTP/2 and gRPC (CVE-2026-42055) (Closes: #1140359) * Charset: fixed another rare buffer overread in recode_from_utf8() (CVE-2026-48142) (Closes: #1140361) ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1140361
#1140361#28
Date:
2026-07-18 16:12:39 UTC
From:
To:
Hello,

Bug #1140361 in nginx reported by you has been fixed in the Git repository.
You can see the commit message below and you can check the diff of the fix at:

https://salsa.debian.org/nginx-team/nginx/-/commit/c2d45bd8fe45473bd592403961e566c30fff5c30
------------------------------------------------------------------------ Import Debian changes 1.22.1-9+deb12u9 nginx (1.22.1-9+deb12u9) bookworm-security; urgency=medium . * Non-maintainer upload by the LTS Team. * debian/gbp.conf: set debian-branch to debian/bookworm. * debian/patches: import upstream patches to fix vulnerabilities. - CVE-2026-42055.patch: backport from upstream; (Closes: #1140359) - CVE-2026-48142.patch: cherry-pick from upstream. (Closes: #1140361) * debian/tests/abicheck: cherry-pick from debain/trixie, remove chown, add warn when it fails and remove needs-root restriction. ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1140361
#1140361#29
Date:
2026-07-18 16:13:34 UTC
From:
To:
Hello,

Bug #1140361 in nginx reported by you has been fixed in the Git repository.
You can see the commit message below and you can check the diff of the fix at:

https://salsa.debian.org/nginx-team/nginx/-/commit/c2d45bd8fe45473bd592403961e566c30fff5c30
------------------------------------------------------------------------ Import Debian changes 1.22.1-9+deb12u9 nginx (1.22.1-9+deb12u9) bookworm-security; urgency=medium . * Non-maintainer upload by the LTS Team. * debian/gbp.conf: set debian-branch to debian/bookworm. * debian/patches: import upstream patches to fix vulnerabilities. - CVE-2026-42055.patch: backport from upstream; (Closes: #1140359) - CVE-2026-48142.patch: cherry-pick from upstream. (Closes: #1140361) * debian/tests/abicheck: cherry-pick from debain/trixie, remove chown, add warn when it fails and remove needs-root restriction. ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1140361