SUSE-CU-2026:7522-1: Security update of private-registry/harbor-portal

sle-container-updates at lists.suse.com sle-container-updates at lists.suse.com
Thu Jul 30 07:08:46 UTC 2026


SUSE Container Update Advisory: private-registry/harbor-portal
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2026:7522-1
Container Tags        : private-registry/harbor-portal:1.1.3 , private-registry/harbor-portal:1.1.3-2.86 , private-registry/harbor-portal:latest
Container Release     : 2.86
Severity              : important
Type                  : security
References            : 1267525 1268492 1268495 CVE-2026-42055 CVE-2026-48142 
-----------------------------------------------------------------

The container private-registry/harbor-portal was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3329-1
Released:    Tue Jul 28 11:34:28 2026
Summary:     Security update for nginx
Type:        security
Severity:    important
References:  1267525,1268492,1268495,CVE-2026-42055,CVE-2026-48142
This update for nginx fixes the following issues

- CVE-2026-42055: heap-based buffer overflow in the `ngx_http_proxy_v2_module` and `ngx_http_grpc_module` modules
  (bsc#1268492).
- CVE-2026-48142: heap buffer over-read in the `ngx_http_charset_module` module (bsc#1268495).
- Remote denial of service via the HTTP/2 bomb exploit (bsc#1267525).


The following package changes have been done:

- system-user-harbor-2.14.4-150700.1.24 updated
- nginx-1.21.5-150600.10.24.1 updated
- harbor-portal-2.14.4-150700.1.24 updated
- container:suse-sle15-15.7-a5e0c95d4920d65d037fe2ab91c98c6e7c6b609d46ff4844855cbfe5770934aa-0 updated


More information about the sle-container-updates mailing list