logo

Nginx Releases Critical Update: Six Vulnerabilities Patched in New Stable Version

ID: 0584f42a-6b93-5d09-8db3-12db63cd2769

STIX ID: report--0584f42a-6b93-5d09-8db3-12db63cd2769

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-05-14

Date Updated: 2026-05-14

Author: Ddos

...
...

nginx 1.30.1 was released to address six security vulnerabilities — notably a CVSSv4 9.2 heap buffer overflow in the ngx_http_rewrite_module (CVE-2026-42945) that can lead to arbitrary code execution in worker processes. Other addressed issues include backend request injection, buffer overreads in SCGI/uWSGI and charset decoding, HTTP/3 address spoofing, and a DNS resolver use-after-free; administrators are advised to update immediately or temporarily disable high-risk directives like proxy_set_body, charset_map, and ssl_ocsp.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.