Nginx Releases Critical Update: Six Vulnerabilities Patched in New Stable Version
ID: 0584f42a-6b93-5d09-8db3-12db63cd2769
STIX ID: report--0584f42a-6b93-5d09-8db3-12db63cd2769
Feed Name: securityonline.info
nginx 1.30.1 was released to address six security vulnerabilities — notably a CVSSv4 9.2 heap buffer overflow in the ngx_http_rewrite_module (CVE-2026-42945) that can lead to arbitrary code execution in worker processes. Other addressed issues include backend request injection, buffer overreads in SCGI/uWSGI and charset decoding, HTTP/3 address spoofing, and a DNS resolver use-after-free; administrators are advised to update immediately or temporarily disable high-risk directives like proxy_set_body, charset_map, and ssl_ocsp.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
