Synopsis
| Issued | 2026-05-25 |
| Severity | Awaiting Analysis |
| Updated Packages | kusanagi-nginx131 |
| Affected Products | Business Edition, KUSANAGI 9, Security Edition |
Description
An update for kusanagi-nginx131 is now available.
Security fix(es):
- Security: a heap memory buffer overflow might occur in a worker process when using a configuration with overlapping captures in ngx_http_rewrite_module, potentially resulting in arbitrary code execution (CVE-2026-9256). Thanks to Mufeed VH of Winfunc Research.
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE information may not yet be available on those websites.