Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Lifecycle catalogue
RELEASE NOTESNGINXVERIFIED

PUBLISHER UPDATE · NGINX-1.31.3

NGINX-1.31.3 release notes and known issues

release-1.31.3

Scope: NGINX. This update record adds version, fix and known-issue context. Its publication date is not a lifecycle boundary.

Summary

nginx-1.31.3 mainline version has been released, with fixes for buffer overflow vulnerability when using map with regex ( CVE-2026-42533 ), memory disclosure vulnerability when using ngx_http_slice_module ( CVE-2026-60005 ), and use-after-free vulnerability when using ngx_http_ssi_module ( CVE-2026-56434 ). See official CHANGES on nginx.org. Below is a release summary generated by GitHub. What's Changed Configure: set cache line size for loongarch64 by @shankerwangmiao in #1489 HTTP/2: fix overlapping memcpy in CONTINUATION frames by @wufengwind in #1486 Add missing bounds check in ngx_{http,stream}_compile_complex_value() by @wufengwind in #1484 Revert "HTTP/2: fixed overlapping memcpy in CONTINUATION frames" by @ac000 in #1517 GH: explicitly set permissions in workflows by @ac000 in #1451 Charset: disabled charset_map with utf-8 in the first column by @pluknet in #1523 Upstream: Upgrade header processing by @vinaykumar-1591 in #1476 Fix setting the IPV6_DONTFRAG socket option by @arut in #1544 Xslt: disable loading of external entities by default by @VadimZhestikov in #1549 SSL: fixed memory leak in ngx_ssl_get_ech_outer_server_name(). by @devnexen in #1471 Fixing HTTP/2 issues by @hongzhidao in #1441 Perl fixes by @pluknet in #1556 Configure: include crypt.h for crypt() feature tests by @bavshin-f5 in #1552 HTTP/2: Reject requests with pseudo-headers after headers by @nitin9977 in #1541 Stream and HTTP: rcvbuf and sndbuf directives for upstream sockets by @patrikwl in #1298 Tunnel body improvements by @arut in #1560 Nginx 1.31.3 security fixes by @arut in #1561 nginx-1.31.3-RELEASE by @pluknet in #1562 New Contributors @shankerwangmiao made their first contribution in #1489 @wufengwind made their first contribution in #1486 @vinaykumar-1591 made their first contribution in #1476 @patrikwl made their first contribution in #1298 Full Changelog : release-1.31.2...release-1.31.3

Improvements and security content

  • nginx-1.31.3 mainline version has been released, with fixes for buffer overflow vulnerability when using map with regex ( CVE-2026-42533 ), memory disclosure vulnerability when using ngx_http_slice_module ( CVE-2026-60005 ), and use-after-free vulnerability when using ngx_http_ssi_module ( CVE-2026-56434 ). See official CHANGES on nginx.org. Below is a release summary generated by GitHub. What's Changed Configure: set cache line size for loongarch64 by @shankerwangmiao in #1489 HTTP/2: fix overlapping memcpy in CONTINUATION frames by @wufengwind in #1486 Add missing bounds check in ngx_{http,stream}_compile_complex_value() by @wufengwind in #1484 Revert "HTTP/2: fixed overlapping memcpy in CONTINUATION frames" by @ac000 in #1517 GH: explicitly set permissions in workflows by @ac000 in #1451 Charset: disabled charset_map with utf-8 in the first column by @pluknet in #1523 Upstream: Upgrade header processing by @vinaykumar-1591 in #1476 Fix setting the IPV6_DONTFRAG socket option by @arut in #1544 Xslt: disable loading of external entities by default by @VadimZhestikov in #1549 SSL: fixed memory leak in ngx_ssl_get_ech_outer_server_name(). by @devnexen in #1471 Fixing HTTP/2 issues by @hongzhidao in #1441 Perl fixes by @pluknet in #1556 Configure: include crypt.h for crypt() feature tests by @bavshin-f5 in #1552 HTTP/2: Reject requests with pseudo-headers after headers by @nitin9977 in #1541 Stream and HTTP: rcvbuf and sndbuf directives for upstream sockets by @patrikwl in #1298 Tunnel body improvements by @arut in #1560 Nginx 1.31.3 security fixes by @arut in #1561 nginx-1.31.3-RELEASE by @pluknet in #1562 New Contributors @shankerwangmiao made their first contribution in #1489 @wufengwind made their first contribution in #1486 @vinaykumar-1591 made their first contribution in #1476 @patrikwl made their first contribution in #1298 Full Changelog : release-1.31.2...release-1.31.3

Known issues

Publisher statement

Not stated. The verified publisher record does not contain a known-issues statement.

Affected products and versions

Products

  • NGINX

Affected versions

  • 1.31.3
  • 1.31.3-RELEASE
  • 1.31.2

Fixed versions or updates

  • No fixed version is stated in this record.

Recommended action

Review the official publisher document before deployment.

Related vulnerabilities

BlackTree CVE Intelligence

Official publisher evidence