RHSA-2026:8346HighCVSS 8.2

Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update

Published
April 15, 2026
Last Modified
August 24, 2026

🔗 CVE IDs covered (8)

📋 Description

CVE-2025-53859 — nginx: NGINX ngx_mail_smtp_module vulnerability CVE-2026-1642 — nginx: NGINX: Data injection via man-in-the-middle attack on TLS proxied connections CVE-2026-27651 — NGINX: NGINX: Denial of Service via undisclosed requests when ngx_mail_auth_http_module is enabled CVE-2026-27654 — NGINX: NGINX: Denial of Service or file modification via buffer overflow in ngx_http_dav_module CVE-2026-27784 — NGINX: NGINX: Denial of Service due to memory corruption via crafted MP4 file CVE-2026-28753 — NGINX: NGINX Plus: NGINX Open Source: NGINX Plus and NGINX Open Source: Request manipulation via header injection in SMTP upstream requests CVE-2026-28755 — NGINX: NGINX: Certificate revocation bypass when OCSP is enabled CVE-2026-32647 — nginx: NGINX: Denial of Service or Code Execution via specially crafted MP4 files

🎯 Affected products5

  • Red Hat Hardened Images
  • nginx-main@aarch64 as a component of Red Hat Hardened Images
  • nginx-main@noarch as a component of Red Hat Hardened Images
  • nginx-main@src as a component of Red Hat Hardened Images
  • nginx-main@x86_64 as a component of Red Hat Hardened Images

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/ Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, disable the ngx_http_mp4_module in your NGINX configuration if MP4 file processing is not required. This can be done by commenting out or removing the mp4 directive from the NGINX configuration file. After modifying the configuration, a reload or restart of the NGINX service is required for the changes to take effect. Alternatively, restrict access to the NGINX server to trusted networks and users to prevent the upload and processing of malicious MP4 files.

🔗 References (12)