SUSE-CU-2026:7484-1: Security update of private-registry/1.2/harbor-portal

sle-container-updates at lists.suse.com sle-container-updates at lists.suse.com
Wed Jul 29 07:05:31 UTC 2026


SUSE Container Update Advisory: private-registry/1.2/harbor-portal
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2026:7484-1
Container Tags        : private-registry/1.2/harbor-portal:1.2.0 , private-registry/1.2/harbor-portal:1.2.0-1.69 , private-registry/1.2/harbor-portal:latest
Container Release     : 1.69
Severity              : important
Type                  : security
References            : 1267525 1268492 1268495 CVE-2026-42055 CVE-2026-48142 
-----------------------------------------------------------------

The container private-registry/1.2/harbor-portal was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3329-1
Released:    Tue Jul 28 11:34:28 2026
Summary:     Security update for nginx
Type:        security
Severity:    important
References:  1267525,1268492,1268495,CVE-2026-42055,CVE-2026-48142
This update for nginx fixes the following issues

- CVE-2026-42055: heap-based buffer overflow in the `ngx_http_proxy_v2_module` and `ngx_http_grpc_module` modules
  (bsc#1268492).
- CVE-2026-48142: heap buffer over-read in the `ngx_http_charset_module` module (bsc#1268495).
- Remote denial of service via the HTTP/2 bomb exploit (bsc#1267525).


The following package changes have been done:

- system-user-harbor-2.15.1-150700.1.22 updated
- nginx-1.21.5-150600.10.24.1 updated
- harbor-portal-2.15.1-150700.1.22 updated
- container:suse-sle15-15.7-0411096f465658d23cf7197d39261fa8d818d8fc75c5ad5ce0e68f97a657663f-0 updated


More information about the sle-container-updates mailing list