nginx 1.31.3 update addressing RCE vulnerability

The release of the main branch nginx 1.31.3 has been formed, within which the development of new features continues, as well as the release of the parallel stable branch nginx 1.30.4, to which only changes related to fixing serious bugs and vulnerabilities are made. The updates fixed 3 vulnerabilities:

  • CVE-2026-42533 — a buffer overflow that occurs when using checks via regular expressions with substitutions in the 'map' directive using unnamed (e.g., $1 and $2) or named variables, provided that the mentioned variables are referenced before the result variable map or a variable that is not cached is used. The vulnerability could potentially lead to remote code execution on server by sending a specially crafted HTTP request. The issue has been assigned a critical danger level of 9.2 out of 10.
  • CVE-2026-60005 — a leak of uninitialized memory in the worker process when using the ngx_http_slice_module and specifying regular expressions with substitutions in the slice directive using unnamed variables. The vulnerability has been assigned a danger level of 8.8 out of 10.
  • CVE-2026-56434 — a memory access after it has been freed in the ngx_http_ssi_module, occurring during the processing of a specially crafted response returned by a proxied backend. The vulnerability could lead to the modification of the worker process's memory content. The issue has been assigned a danger level of 8.3 out of 10.

Non-vulnerability-related changes:

  • The ngx_http_xslt_filter_module has been updated to disable loading variables in the XML document whose values are loaded from external sources. A directive 'xml_external_entities' has been added to control the loading of external components specified in the DTD block of the processed XML document.
  • Directives 'proxy_socket_sndbuf', 'proxy_socket_rcvbuf', 'fastcgi_socket_sndbuf', 'fastcgi_socket_rcvbuf', 'grpc_socket_sndbuf', 'grpc_socket_rcvbuf', 'scgi_socket_sndbuf', 'scgi_socket_rcvbuf', 'uwsgi_socket_sndbuf', 'uwsgi_socket_rcvbuf', 'tunnel_socket_sndbuf', and 'tunnel_socket_rcvbuf' have been added to set the send buffer size (SO_SNDBUF) and receive buffer size (SO_RCVBUF).
  • For the LoongArch64 architecture, a definition of the block size (cache line) used for data transfer between the CPU cache and memory has been implemented.
  • The ngx_http_proxy_v2_module and ngx_http_grpc_module modules implement a limitation on the size of headers and trailers in HTTP/2 responses using the directives proxy_buffer_size and grpc_buffer_size.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster