logo

Critical CVE Fixes Released for Fedora Nginx Modules

ID: 379aa7f4-202a-518d-8526-a056f95da61c

STIX ID: report--379aa7f4-202a-518d-8526-a056f95da61c

Feed Name: ThreatCluster

Threat Score
70/100

Date Published: 2026-06-27

Date Updated: 2026-06-27

...
...

On June 17, 2026, three critical CVEs affecting multiple Fedora Nginx modules (nginx-mod-fancyindex, nginx-mod-modsecurity, nginx-mod-headers-more, nginx-mod-brotli, nginx-mod-naxsi, nginx-mod-js-challenge, nginx-mod-vts) were disclosed, potentially allowing remote code execution and denial-of-service. A public proof-of-concept appeared on June 19, 2026; Fedora 43 and 44 users are strongly advised to install the available patches via dnf immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.