CVE status check

Derek Shiell dshiell at netflix.com
Wed Jul 22 22:24:05 UTC 2026


Hello,

Has FreeNGINX assessed the following NGINX security issues, and do
they affect the current FreeNGINX release?

   - CVE-2026-42533 — regex captures and map
   - CVE-2026-60005 — ngx_http_slice_module
   - CVE-2026-56434 — ngx_http_ssi_module

Our downstream build is based on FreeNGINX 1.31.1 and enable and
configure the slice module, so CVE-2026-60005 is particularly
relevant.

Are fixes planned for a FreeNGINX point release? If so, is there an
expected version or timeline?
Otherwise, are there recommended commits for downstreams to backport?

References:
- https://nvd.nist.gov/vuln/detail/CVE-2026-42533
- https://nvd.nist.gov/vuln/detail/CVE-2026-60005
- https://nvd.nist.gov/vuln/detail/CVE-2026-56434
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://freenginx.org/pipermail/nginx/attachments/20260722/1aa31737/attachment.htm>


More information about the nginx mailing list