Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Lifecycle catalogue
RELEASE NOTESNGINXVERIFIED

PUBLISHER UPDATE · NGINX-1.30.3

NGINX-1.30.3 release notes and known issues

release-1.30.3

Scope: NGINX. This update record adds version, fix and known-issue context. Its publication date is not a lifecycle boundary.

Summary

nginx-1.30.3 stable version has been released, with fixes for buffer overflow vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module ( CVE-2026-42055 ), and buffer overread vulnerability in the ngx_http_charset_module ( CVE-2026-48142 ). See official CHANGES-1.30 on nginx.org. Below is a release summary generated by GitHub. What's Changed Nginx 1.30.3 with security fixes by @arut in #1475 Full Changelog : release-1.30.2...release-1.30.3

Improvements and security content

  • nginx-1.30.3 stable version has been released, with fixes for buffer overflow vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module ( CVE-2026-42055 ), and buffer overread vulnerability in the ngx_http_charset_module ( CVE-2026-48142 ). See official CHANGES-1.30 on nginx.org. Below is a release summary generated by GitHub. What's Changed Nginx 1.30.3 with security fixes by @arut in #1475 Full Changelog : release-1.30.2...release-1.30.3

Known issues

Publisher statement

Not stated. The verified publisher record does not contain a known-issues statement.

Affected products and versions

Products

  • NGINX

Affected versions

  • 1.30.3
  • 1.30
  • 1.30.2

Fixed versions or updates

  • No fixed version is stated in this record.

Recommended action

Review the official publisher document before deployment.

Related vulnerabilities

BlackTree CVE Intelligence

Official publisher evidence