NG
Nginx 1.31.3
Get release alerts
1.31.2โ1.31.3SecurityBug fix
โฆ Editor's summary
NGINX 1.31.3 is a security-focused mainline release that fixes three vulnerabilities affecting the map directive, ngx_http_slice_module, and ngx_http_ssi_module. The release also includes additional internal validation to prevent buffer overruns and several stability fixes across HTTP/3, gRPC, mail proxy, gzip, Perl, and charset modules.
โ Security impact
- Fixed a buffer overflow vulnerability when using the
mapdirective with regular expressions (CVE-2026-42533). - Fixed a memory disclosure vulnerability in
ngx_http_slice_module(CVE-2026-60005). - Fixed a use-after-free vulnerability in
ngx_http_ssi_module(CVE-2026-56434). - Upgrade is strongly recommended for all deployments running NGINX 1.31.2 or earlier.
What's new
- Updated NGINX to version 1.31.3.
- Resolved three security vulnerabilities affecting the map, slice, and SSI modules.
- Added additional validation during variable substitution to help prevent buffer overruns.
- Fixed stability issues in HTTP/3, gRPC, mail proxy, gzip, Perl, and charset modules.
- Resolved several worker process crash scenarios and improved overall reliability.
- Recommended upgrade for all users running the NGINX 1.31.x mainline branch.
Latest in Web Servers
๐ฌ Comments (0)
Share any installation issues, compatibility changes, or fixes you noticed.