Skip to content

Update nginx to 1.30.4 to fix CVE-2026-42533 (5.0-9.1.1 branch) - #1666

Open
Mosherfist wants to merge 1 commit into
vmware:5.0-9.1.1from
Mosherfist:fix/nginx-cve-2026-42533-5.0-9.1.1-branch
Open

Update nginx to 1.30.4 to fix CVE-2026-42533 (5.0-9.1.1 branch)#1666
Mosherfist wants to merge 1 commit into
vmware:5.0-9.1.1from
Mosherfist:fix/nginx-cve-2026-42533-5.0-9.1.1-branch

Conversation

@Mosherfist

Copy link
Copy Markdown

Follow-up to #1663 for the 5.0-9.1.1 branch, per @danielxdd's request.

Summary

Bumps nginx from 1.26.3 to 1.30.4 on the 5.0-9.1.1 branch to fix
CVE-2026-42533, a critical heap buffer overflow (CVSS 9.2) in nginx's
map directive regex handling.

Changes

This branch mirrors the same structure as the 5.0 branch (#1664), so
the fix is identical.

References

Testing

Not build-tested locally; relying on CI for build validation.

Fixes a critical heap buffer overflow in nginx's map directive regex
handling (CVSS 9.2). The vulnerable range is 0.9.6 through 1.31.2;
this bumps the 5.0-9.1.1 branch's nginx package to the patched
1.30.4 stable release.

The six CVE backport patches (CVE-2025-53859, CVE-2026-27654,
CVE-2026-32647, CVE-2026-27651, CVE-2026-27784, CVE-2026-1642)
previously applied on top of 1.26.3 are dropped, as all six fixes
are included upstream in 1.30.4.

See: https://nginx.org/en/CHANGES
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant