N

NGINX

N
NGINX Networking v1.31.3

release-1.31.3

nginx-1.31.3 mainline version has been released, with fixes for buffer overflow vulnerability when using map with regex (CVE-2026-42533), memory disclosure vulnerability when using ngx_http_slice_module (CVE-2026-60005), and use-after-free vulnerability when using ngx_http_ssi_module (CVE-2026-56434). See official CHANGES on nginx.org. Below is a release summary generated by GitHub. What's Changed…

N
NGINX Networking v1.30.4

release-1.30.4

nginx-1.30.4 stable version has been released, with fixes for buffer overflow vulnerability when using map with regex (CVE-2026-42533), memory disclosure vulnerability when using ngx_http_slice_module (CVE-2026-60005), and use-after-free vulnerability when using ngx_http_ssi_module (CVE-2026-56434). See official CHANGES-1.30 on nginx.org. Below is a release summary generated by GitHub. What's Chan…

N
NGINX Networking v1.30.3

release-1.30.3

nginx-1.30.3 stable version has been released, with fixes for buffer overflow vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module (CVE-2026-42055), and buffer overread vulnerability in the ngx_http_charset_module (CVE-2026-48142). See official CHANGES-1.30 on nginx.org. Below is a release summary generated by GitHub. What's Changed Nginx 1.30.3 with security fixes by @arut in #1…

N
NGINX Networking v1.31.2

release-1.31.2

nginx-1.31.2 mainline version has been released, with fixes for use-after-free vulnerability in the ngx_http_v3_module (CVE-2026-42530), buffer overflow vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module (CVE-2026-42055), and buffer overread vulnerability in the ngx_http_charset_module (CVE-2026-48142). See official CHANGES on nginx.org. Below is a release summary generated by…

N
NGINX Networking v1.31.1

release-1.31.1

nginx-1.31.1 mainline version has been released, with a fix for buffer overflow vulnerability in the ngx_http_rewrite_module (CVE-2026-9256). See official CHANGES on nginx.org. Below is a release summary generated by GitHub. What's Changed Fix the set-creation-date.yaml workflow by @ac000 in #1353 Mp4: avoid adding or comparing to null pointer by @arut in #1360 HTTP/2: limit Content-Type and Locat…

N
NGINX Networking v1.30.2

release-1.30.2

nginx-1.30.2 stable version has been released, with a fix for buffer overflow vulnerability in the ngx_http_rewrite_module (CVE-2026-9256). See official CHANGES-1.30 on nginx.org. Below is a release summary generated by GitHub. What's Changed nginx-1.30.2-RELEASE by @pluknet in #1397 Full Changelog: release-1.30.1...release-1.30.2

N
NGINX Networking v1.31.0

release-1.31.0

nginx-1.31.0 mainline version has been released with fixes for HTTP/2 request injection vulnerability in the ngx_http_proxy_module (CVE-2026-42926), buffer overflow vulnerability in the ngx_http_rewrite_module (CVE-2026-42945), buffer overread vulnerabilities in the ngx_http_scgi_module and ngx_http_uwsgi_module (CVE-2026-42946), buffer overread vulnerability in the ngx_http_charset_module (CVE-20…

N
NGINX Networking v1.30.1

release-1.30.1

nginx-1.30.1 stable version has been released with fixes for HTTP/2 request injection vulnerability in the ngx_http_proxy_module (CVE-2026-42926), buffer overflow vulnerability in the ngx_http_rewrite_module (CVE-2026-42945), buffer overread vulnerabilities in the ngx_http_scgi_module and ngx_http_uwsgi_module (CVE-2026-42946), buffer overread vulnerability in the ngx_http_charset_module (CVE-2026…

N
NGINX Networking v1.30.0

release-1.30.0

nginx-1.30.0 stable version has been released, incorporating new features and bug fixes from the 1.29.x mainline branch — including Early Hints, HTTP/2 to backend and Encrypted ClientHello, sticky sessions support for upstreams, Multipath TCP support, the default proxy HTTP version set to HTTP/1.1 with keep-alive enabled, and more. What's Changed Version bump 1.29.0 by @arut in #632 QUIC: silence…

N
NGINX Networking v1.29.8

release-1.29.8

nginx-1.29.8 mainline version has been released. See official CHANGES on nginx.org. Below is a release summary generated by GitHub. What's Changed Fixed the "include" directive inside the "geo" block. by @jimf5 in #1184 SSL: compatibility with OpenSSL 4.0. by @pluknet in #1183 Update CONTRIBUTING.md by @xuruidong in #1195 Upstream: fixed processing multiple 103 (early hints) responses. by @pluknet…

N
NGINX Networking v1.29.7

release-1.29.7

nginx-1.29.7 mainline version has been released, introducing two significant updates: support for Multipath TCP and upgrading the default HTTP version to HTTP/1.1 with keep-alive enabled. This release also includes a security fix for the buffer overflow vulnerability in the ngx_http_dav_module (CVE-2026-27654), security fixes for the buffer overflow vulnerabilities in the ngx_http_mp4_module (CVE-…

N
NGINX Networking v1.28.3

release-1.28.3

nginx-1.28.3 stable version has been released. This release includes a security fix for the buffer overflow vulnerability in the ngx_http_dav_module (CVE-2026-27654), security fixes for the buffer overflow vulnerabilities in the ngx_http_mp4_module (CVE-2026-27784, CVE-2026-32647), security fixes for the mail session authentication vulnerabilities (CVE-2026-27651, CVE-2026-28753), and a security f…