nginx release-1.31.1

release-1.31.1
Changed 2
  • Limit Content-Type and Location response header length in HTTP/2
  • Harden escape flags control in rewrite module
Fixed 3
  • Avoid adding or comparing to null pointer in mp4 module
  • Fix mail error path handling
  • Fix buffer overflow with overlapping captures in rewrite module
Security 1
  • Fix buffer overflow vulnerability in the ngx_http_rewrite_module (CVE-2026-9256)

nginx-1.31.1 mainline version has been released, with a fix for buffer overflow vulnerability in the ngx_http_rewrite_module (CVE-2026-9256).

See official CHANGES on nginx.org.

Below is a release summary generated by GitHub.

What's Changed

Full Changelog: https://github.com/nginx/nginx/compare/release-1.31.0...release-1.31.1

View original

Upgraded? How did it go?

Discussion