Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Lifecycle catalogue
RELEASE NOTESNGINXVERIFIED

PUBLISHER UPDATE · NGINX-1.31.1

NGINX-1.31.1 release notes and known issues

release-1.31.1

Scope: NGINX. This update record adds version, fix and known-issue context. Its publication date is not a lifecycle boundary.

Summary

nginx-1.31.1 mainline version has been released, with a fix for buffer overflow vulnerability in the ngx_http_rewrite_module ( CVE-2026-9256 ). See official CHANGES on nginx.org. Below is a release summary generated by GitHub. What's Changed Fix the set-creation-date.yaml workflow by @ac000 in #1353 Mp4: avoid adding or comparing to null pointer by @arut in #1360 HTTP/2: limit Content-Type and Location response header length by @arut in #1359 Mail error path fixes by @arut in #1358 Rewrite: harden escape flags control by @arut in #1381 Rewrite: fix buffer overflow with overlapping captures by @arut in #1395 nginx-1.31.1-RELEASE by @pluknet in #1396 Full Changelog : release-1.31.0...release-1.31.1

Improvements and security content

  • nginx-1.31.1 mainline version has been released, with a fix for buffer overflow vulnerability in the ngx_http_rewrite_module ( CVE-2026-9256 ). See official CHANGES on nginx.org. Below is a release summary generated by GitHub. What's Changed Fix the set-creation-date.yaml workflow by @ac000 in #1353 Mp4: avoid adding or comparing to null pointer by @arut in #1360 HTTP/2: limit Content-Type and Location response header length by @arut in #1359 Mail error path fixes by @arut in #1358 Rewrite: harden escape flags control by @arut in #1381 Rewrite: fix buffer overflow with overlapping captures by @arut in #1395 nginx-1.31.1-RELEASE by @pluknet in #1396 Full Changelog : release-1.31.0...release-1.31.1

Known issues

Publisher statement

Not stated. The verified publisher record does not contain a known-issues statement.

Affected products and versions

Products

  • NGINX

Affected versions

  • 1.31.1
  • 1.31.1-RELEASE
  • 1.31.0

Fixed versions or updates

  • No fixed version is stated in this record.

Recommended action

Review the official publisher document before deployment.

Related vulnerabilities

BlackTree CVE Intelligence

Official publisher evidence