Nginx 1.31.3 update fixes RCE vulnerability

The main nginx 1.31.3 branch has been released, continuing development of new features. The parallel stable branch, nginx 1.30.4, is also being released, containing only changes related to fixing serious bugs and vulnerabilities. These updates address three vulnerabilities:

  • CVE-2026-42533 — A buffer overflow occurs when the "map" directive uses regular expression checks with substitutions using unnamed (e.g., $1 and $2) or named variables, provided that these variables are mentioned before the map result variable or a variable that is not cached is used. This vulnerability could potentially lead to remote code execution. server by sending a specially crafted HTTP request. This issue has been rated as critical (9.2 out of 10).
  • CVE-2026-60005 — An uninitialized memory leak in a worker process occurs when using the ngx_http_slice_module module and specifying regular expression substitutions using unnamed variables in the slice directive. This vulnerability has a severity level of 8.8 out of 10.
  • CVE-2026-56434 is a use-after-free vulnerability in the ngx_http_ssi_module module that occurs when processing a specially crafted response returned by a proxied backend. This vulnerability can lead to modification of worker process memory. This issue is rated at a severity level of 8.3 out of 10.

Non-vulnerability related changes:

  • In the ngx_http_xslt_filter_module module, loading of variables in XML documents whose values ​​are loaded from external sources has been disabled. The "xml_external_entities" directive has been added to control the loading of external components specified in the DTD block of the processed XML document.
  • Added directives "proxy_socket_sndbuf", "proxy_socket_rcvbuf", "fastcgi_socket_sndbuf", "fastcgi_socket_rcvbuf", "grpc_socket_sndbuf", "grpc_socket_rcvbuf", "scgi_socket_sndbuf", "scgi_socket_rcvbuf", "uwsgi_socket_sndbuf", "uwsgi_socket_rcvbuf", "tunnel_socket_sndbuf" and "tunnel_socket_rcvbuf" to set the size of the send (SO_SNDBUF) and receive (SO_RCVBUF) buffers.
  • For the LoongArch64 architecture, the definition of the block size (cache line) used to transfer data between the CPU cache and memory has been implemented.
  • The ngx_http_proxy_v2_module and ngx_http_grpc_module modules implement a limit on the size of headers and trailers in HTTP/2 responses using the proxy_buffer_size and grpc_buffer_size directives.

Source: opennet.ru

Buy reliable hosting for sites with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster