CVE-2026-56434
HighAdvisory
Published 15 Jul 2026In the index since 5 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 8.3
- base score, highest
- EPSS
- 0.004
- 38th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 103
- of 17,781 indexed, latest versions
- Container images
- 103
- deployed by those charts
- Fix available
- 5 of 5
- affected packages
NGINX ngx_http_ssi_module vulnerability
Carried by container images the latest versions of 103 of 17,781 indexed charts deploy, on 103 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| nginxdeb | 1.4.6-1ubuntu3.8ppa1, 1.18.0-0ubuntu1.2, 1.18.0-0ubuntu1.3, 1.18.0-0ubuntu1.4+30 more | 1.18.0-6ubuntu14.17, 1.24.0-2ubuntu7.14, 1.26.3-3+deb13u8 | 82 |
| nginxapk | 1.26.2-r4, 1.26.3-r0, 1.28.0-r3, 1.28.1-r1+4 more | 1.26.3-r2, 1.28.3-r6 | 14 |
| nginxbitnami | 1.25.5-0, 1.27.1-2, 1.28.0-0, 1.31.3-0 | 1.30.4 | 4 |
| nginx-mainlineapk | 1.27.4-r0, 1.27.4-r2, 1.29.8-r1 | 1.31.3-r0 | 3 |
| NGINX Open Sourcebitnami | 1.25.5-0 | 1.30.4 | 1 |
- OSV records
- ALPINE-CVE-2026-56434BIT-nginx-2026-56434CGA-35p6-397x-pf84DEBIAN-CVE-2026-56434UBUNTU-CVE-2026-56434
- Also known as
- BIT-nginx-gateway-2026-56434, CGA-cjff-ffmj-gw2w, USN-8563-1
Charts affected
103 by stars
Container images carrying it
103 by charts deploying them
A fixed version is listed for 5 of the 5 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| ghcr.io/ | e65123a43ecc | nginx | 1.26.3-3+deb13u8 | 1 |
| public.ecr.aws/ | 34823c8abe00 | nginx | no fix listed | 1 |
| public.ecr.aws/ | f8fb4eea4071 | nginx | no fix listed | 1 |