CVE-2026-42055
CriticalAdvisory
Published 17 Jun 2026In the index since 5 Sept 2026
- Severity
- Critical
- worst across findings
- CVSS
- 9.2
- base score, highest
- EPSS
- 0.065
- 93rd percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 52
- of 17,781 indexed, latest versions
- Container images
- 52
- deployed by those charts
- Fix available
- 4 of 4
- affected packages
Red Hat Security Advisory: nginx security, bug fix, and enhancement update
Carried by container images the latest versions of 52 of 17,781 indexed charts deploy, on 52 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| nginxdeb | 1.4.6-1ubuntu3.8ppa1, 1.18.0-0ubuntu1.2, 1.18.0-0ubuntu1.3, 1.18.0-0ubuntu1.4+15 more | 1.18.0-6ubuntu14.16, 1.22.1-9+deb12u9, 1.24.0-2ubuntu7.13, 1.26.3-3+deb13u7 | 25 |
| nginxapk | 1.26.2-r4, 1.26.3-r0, 1.28.0-r3, 1.28.1-r1+4 more | 1.26.3-r2, 1.28.3-r4 | 14 |
| nginx-mainlineapk | 1.27.4-r0, 1.27.4-r2, 1.29.8-r1 | 1.31.2-r0 | 3 |
| nginxrpm | 1:1.14.1-9.module+el8.0.0+4108+af250afe, 1:1.20.1-1.module+el8.8.0+20359+9bd89172.1, 1:1.20.1-13.el9, 1:1.22.1-5.module+el9.3.0.z+20438+032561a0+3 more | 1:1.24.0-3.module+el8.10.0+24503+61c7c092.3, 2:1.20.1-28.el9_8.4 | 10 |
- OSV records
- ALPINE-CVE-2026-42055CGA-jwcx-pm9x-r4g6DEBIAN-CVE-2026-42055RHSA-2026:36331RHSA-2026:38847UBUNTU-CVE-2026-42055
- Also known as
- CGA-v6vc-x295-wqcr, RHSA-2026:36618, RHSA-2026:36639, USN-8458-1
Charts affected
52 by stars
Container images carrying it
52 by charts deploying them
A fixed version is listed for 4 of the 4 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| quay.io/ | 841b70cd1424 | nginx | 2:1.20.1-28.el9_8.4 | 1 |
| quay.io/ | dcf24040cc77 | nginx | 2:1.20.1-28.el9_8.4 | 1 |