Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Lifecycle catalogue
RELEASE NOTESNGINXVERIFIED

PUBLISHER UPDATE · NGINX-1.31.6

NGINX-1.31.6 release notes and known issues

release-1.31.6

Scope: NGINX. This update record adds version, fix and known-issue context. Its publication date is not a lifecycle boundary.

Summary

nginx-1.31.6 mainline version has been released, with fixes for buffer overflow vulnerability when using ngx_http_v3_module ( CVE-2026-90439 ). See official CHANGES on nginx.org. Below is a release summary generated by GitHub. What's Changed man page updates by @pluknet in #1727 Handle predicate location variable error by @arut in #1750 Handle nested location lookup error by @arut in #1751 Control API: fixed socket inheritance on binary upgrade by @pluknet in #1760 Geo: check binary base CRC32 before relocation by @pluknet in #1739 QUIC compatibility layer fix by @pluknet in #1769 nginx-1.31.6-RELEASE by @pluknet in #1770 Full Changelog : release-1.31.5...release-1.31.6

Improvements and security content

  • nginx-1.31.6 mainline version has been released, with fixes for buffer overflow vulnerability when using ngx_http_v3_module ( CVE-2026-90439 ). See official CHANGES on nginx.org. Below is a release summary generated by GitHub. What's Changed man page updates by @pluknet in #1727 Handle predicate location variable error by @arut in #1750 Handle nested location lookup error by @arut in #1751 Control API: fixed socket inheritance on binary upgrade by @pluknet in #1760 Geo: check binary base CRC32 before relocation by @pluknet in #1739 QUIC compatibility layer fix by @pluknet in #1769 nginx-1.31.6-RELEASE by @pluknet in #1770 Full Changelog : release-1.31.5...release-1.31.6

Known issues

Publisher statement

Not stated. The verified publisher record does not contain a known-issues statement.

Affected products and versions

Products

  • NGINX

Affected versions

  • 1.31.6
  • 1.31.6-RELEASE
  • 1.31.5

Fixed versions or updates

  • No fixed version is stated in this record.

Recommended action

Review the official publisher document before deployment.

Related vulnerabilities

BlackTree CVE Intelligence

Official publisher evidence