release-1.31.6
Checked 29 Sep 2026. BlackTree preserves the last verified facts if a later source check is temporarily unavailable.
Open the official publisher sourcePUBLISHER UPDATE · NGINX-1.31.6
release-1.31.6
Scope: NGINX. This update record adds version, fix and known-issue context. Its publication date is not a lifecycle boundary.
nginx-1.31.6 mainline version has been released, with fixes for buffer overflow vulnerability when using ngx_http_v3_module ( CVE-2026-90439 ). See official CHANGES on nginx.org. Below is a release summary generated by GitHub. What's Changed man page updates by @pluknet in #1727 Handle predicate location variable error by @arut in #1750 Handle nested location lookup error by @arut in #1751 Control API: fixed socket inheritance on binary upgrade by @pluknet in #1760 Geo: check binary base CRC32 before relocation by @pluknet in #1739 QUIC compatibility layer fix by @pluknet in #1769 nginx-1.31.6-RELEASE by @pluknet in #1770 Full Changelog : release-1.31.5...release-1.31.6
Not stated. The verified publisher record does not contain a known-issues statement.
Review the official publisher document before deployment.
Checked 29 Sep 2026. BlackTree preserves the last verified facts if a later source check is temporarily unavailable.
Open the official publisher source