-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 15 May 2026 14:13:33 +0000 Source: nginx Binary: nginx-common nginx-core nginx-dev nginx-doc nginx-full nginx-light Architecture: all Version: 1.26.3-3+deb13u5 Distribution: trixie-security Urgency: medium Maintainer: all Build Daemon (x86-csail-02) Changed-By: Jan Mojžíš Description: nginx-common - small, powerful, scalable web/proxy server - common files nginx-core - nginx web/proxy server (standard version) nginx-dev - nginx web/proxy server - development headers nginx-doc - small, powerful, scalable web/proxy server - documentation nginx-full - nginx web/proxy server (standard version with 3rd parties) nginx-light - nginx web/proxy server (basic version) Changes: nginx (1.26.3-3+deb13u5) trixie-security; urgency=medium . * backport changes from upstream nginx, HTTP/3 address spoofing (CVE-2026-40460), buffer overflow in the ngx_http_rewrite_module (CVE-2026-42945), buffer overread in the ngx_http_scgi_module and ngx_http_uwsgi_module (CVE-2026-42946), resolver use-after-free in OCSP (CVE-2026-40701), buffer overread in the ngx_http_charset_module (CVE-2026-42934) * d/p/CVE-2026-40460.patch add * d/p/CVE-2026-42945.patch add * d/p/CVE-2026-42946.patch add * d/p/CVE-2026-40701.patch add * d/p/CVE-2026-42934.patch add Checksums-Sha1: d654712494f8a14d4f0116473cf1c280ded59e7b 110760 nginx-common_1.26.3-3+deb13u5_all.deb 20a44e5c3c85314dacc98cfc5d95098a4d44ee29 83972 nginx-core_1.26.3-3+deb13u5_all.deb 7c898db5a4251741f74efa7e254b72d362c47ee8 196804 nginx-dev_1.26.3-3+deb13u5_all.deb 68298ea68cf54b4f0bb74390cf2c613aea57db27 92064 nginx-doc_1.26.3-3+deb13u5_all.deb 242048c21327582ca2abb6b74e3ffc0390d9b39e 83988 nginx-full_1.26.3-3+deb13u5_all.deb 837ae42cff1014830974334aaa680e9a114d030e 83736 nginx-light_1.26.3-3+deb13u5_all.deb fa85b9c99d414f04c231a01485fb2f3687fc7502 9783 nginx_1.26.3-3+deb13u5_all-buildd.buildinfo Checksums-Sha256: 02462e4e26289a85449897208928a04dd40eaa7a0dc95335ae63191aa436e624 110760 nginx-common_1.26.3-3+deb13u5_all.deb e0fb846441cdcc9ba773d5786491e4aa7ee578ceafc150eb28e1d5f8ad6ec938 83972 nginx-core_1.26.3-3+deb13u5_all.deb 2442145a8736456f278c2967e04f99a18014b5212e7310403aea5edd24b35720 196804 nginx-dev_1.26.3-3+deb13u5_all.deb 63f8f739c39ae49495b68b94790333a0af395b3e29acc6e2bb5d65e729cf5bfa 92064 nginx-doc_1.26.3-3+deb13u5_all.deb 6b8397594c5270b35ded8792b0976c37cea98a4ec0b7b273810a077ccbb9e7e0 83988 nginx-full_1.26.3-3+deb13u5_all.deb 860009c3670520b82251a3c54e70fd76727b61d85ba992d03d07f00bd3b50289 83736 nginx-light_1.26.3-3+deb13u5_all.deb 4fd26efca9529deb6bbb1f4e583e2173185084e2f4d77b8587f0d805c10d99a2 9783 nginx_1.26.3-3+deb13u5_all-buildd.buildinfo Files: a69d72cbb9c67a76b13258686ed016f9 110760 httpd optional nginx-common_1.26.3-3+deb13u5_all.deb 51174dfd7cb4c9e9ae5aa835243ec30f 83972 httpd optional nginx-core_1.26.3-3+deb13u5_all.deb cb078fea1719e9e1c786b5a4d1c2f357 196804 httpd optional nginx-dev_1.26.3-3+deb13u5_all.deb ed2631cbd390718f2eafe27fd468f38d 92064 doc optional nginx-doc_1.26.3-3+deb13u5_all.deb 8f012a48661e04f7898c8d786032cd59 83988 httpd optional nginx-full_1.26.3-3+deb13u5_all.deb 46178d261fdda4e4c4e585079d9a6a59 83736 httpd optional nginx-light_1.26.3-3+deb13u5_all.deb a7d0137b0c6b834c0f264defbdc259ab 9783 httpd optional nginx_1.26.3-3+deb13u5_all-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEXLxUpUHQBQBTDtd4aBVi67oXtfkFAmoIC/wACgkQaBVi67oX tfnGdRAAtkxDTK+9+AaMfCzE+Yqwqc7ygHStr/L07YJruPHS62MWU4MfOkqV83f8 3drL+/tEmI/8FKIiNn8brWc9onPDklgphnH85w2SzcUeaSc+X4qyBRM5sd7nEBXY dcDO+IiL6EJW3HuBGiE0r5iduAwrjUsuFxVZuoS7HaXmIx3T8xduyeeTipUp6yca hHO38xT2t+Ti12Ae9arivf2Ig6EcYTKg/BnUhxeqyS4DZploEgKCqZjw1RfxW+z0 tzWuINlLIeiz8briiow4a15BGxBxaPhPzJ3pn0X5RCOrE8DGRPzXR40ob2DIQtHP 4OSpHzthgjtgNIH/8s4I0ZfCUCnd3IwRJDKp4bivRgylMg8m5zGrfQIwChC90J0/ W/UnmOwOZWf+IsPOU3D6HkBBU49+eOEybbsWMXZV8QyhPPlCxcuR1hmnMXTxslX9 kwm0ULSzRtfptjf3fzqgibB7+JkAv8kjCOAQpVZAYDGpyS9KHdz1E6UtYliOzcOS xybtIhBb2TrB0GQ9d96hPhlrylDMsaQgx/3SS4oXdPifHSBbwREXtl/8/juTgqmv xNjO/DHFCUa9Dm5soQ9FJAIhXB+j7CIqiRHT4x6Q/1lZbpperYyFOxB6f0stqUAH IkNyTnDuBSovq3vmk0u1UlYhS3pA58zoxYwSTzVca9+hbEQMPQU= =2AVF -----END PGP SIGNATURE-----