Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Lifecycle catalogue
RELEASE NOTESNGINXVERIFIED

PUBLISHER UPDATE · NGINX-1.30.4

NGINX-1.30.4 release notes and known issues

release-1.30.4

Scope: NGINX. This update record adds version, fix and known-issue context. Its publication date is not a lifecycle boundary.

Summary

nginx-1.30.4 stable version has been released, with fixes for buffer overflow vulnerability when using map with regex ( CVE-2026-42533 ), memory disclosure vulnerability when using ngx_http_slice_module ( CVE-2026-60005 ), and use-after-free vulnerability when using ngx_http_ssi_module ( CVE-2026-56434 ). See official CHANGES-1.30 on nginx.org. Below is a release summary generated by GitHub. What's Changed Nginx 1.30.4 by @arut in #1563 Full Changelog : release-1.30.3...release-1.30.4

Improvements and security content

  • nginx-1.30.4 stable version has been released, with fixes for buffer overflow vulnerability when using map with regex ( CVE-2026-42533 ), memory disclosure vulnerability when using ngx_http_slice_module ( CVE-2026-60005 ), and use-after-free vulnerability when using ngx_http_ssi_module ( CVE-2026-56434 ). See official CHANGES-1.30 on nginx.org. Below is a release summary generated by GitHub. What's Changed Nginx 1.30.4 by @arut in #1563 Full Changelog : release-1.30.3...release-1.30.4

Known issues

Publisher statement

Not stated. The verified publisher record does not contain a known-issues statement.

Affected products and versions

Products

  • NGINX

Affected versions

  • 1.30.4
  • 1.30
  • 1.30.3

Fixed versions or updates

  • No fixed version is stated in this record.

Recommended action

Review the official publisher document before deployment.

Related vulnerabilities

BlackTree CVE Intelligence

Official publisher evidence