<div dir="ltr"><pre style="">Hello,<br><br>Has FreeNGINX assessed the following NGINX security issues, and do they affect the current FreeNGINX release?<br><ul><li>CVE-2026-42533 — regex captures and map</li><li>CVE-2026-60005 — ngx_http_slice_module</li><li>CVE-2026-56434 — ngx_http_ssi_module</li></ul>Our downstream build is based on FreeNGINX 1.31.1 and enable and configure the slice module, so CVE-2026-60005 is particularly relevant.<br><br>Are fixes planned for a FreeNGINX point release? If so, is there an expected version or timeline?<br>Otherwise, are there recommended commits for downstreams to backport?<font color="#000000"><span style="text-wrap-mode: wrap;"><br><br>References:
- <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42533">https://nvd.nist.gov/vuln/detail/CVE-2026-42533</a><br>- <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-60005">https://nvd.nist.gov/vuln/detail/CVE-2026-60005</a><br>- <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-56434">https://nvd.nist.gov/vuln/detail/CVE-2026-56434</a></span></font></pre></div>