NG

Nginx 1.31.3

Get release alerts
1.31.2โ†’1.31.3SecurityBug fix
๐Ÿ“… July 15, 2026๐Ÿ—‚ Web Servers๐Ÿ“ฆ Nginx โ†—๐Ÿ“œ Full changelog โ†—
โœฆ Editor's summary

NGINX 1.31.3 is a security-focused mainline release that fixes three vulnerabilities affecting the map directive, ngx_http_slice_module, and ngx_http_ssi_module. The release also includes additional internal validation to prevent buffer overruns and several stability fixes across HTTP/3, gRPC, mail proxy, gzip, Perl, and charset modules.

โš  Security impact
  • Fixed a buffer overflow vulnerability when using the map directive with regular expressions (CVE-2026-42533).
  • Fixed a memory disclosure vulnerability in ngx_http_slice_module (CVE-2026-60005).
  • Fixed a use-after-free vulnerability in ngx_http_ssi_module (CVE-2026-56434).
  • Upgrade is strongly recommended for all deployments running NGINX 1.31.2 or earlier.

What's new

  • Updated NGINX to version 1.31.3.
  • Resolved three security vulnerabilities affecting the map, slice, and SSI modules.
  • Added additional validation during variable substitution to help prevent buffer overruns.
  • Fixed stability issues in HTTP/3, gRPC, mail proxy, gzip, Perl, and charset modules.
  • Resolved several worker process crash scenarios and improved overall reliability.
  • Recommended upgrade for all users running the NGINX 1.31.x mainline branch.
More from Nginx
Nginx 1.31.4Aug 20, 2026
Nginx 1.31.2SecurityBug fixJun 17, 2026
Latest in Web Servers
Apache HTTP Server: Apache HTTP Server 2.4.68SecurityFeatureBug fixJun 8, 2026

๐Ÿ’ฌ Comments (0)

Have you installed this Nginx update?

Share any installation issues, compatibility changes, or fixes you noticed.