Skip to main content

Nginx 1.31.6

Release Date: September 15, 2026

nginx-1.31.6, the mainline version, was released on September 15, 2026. This is a security-focused update that also ships alongside the stable nginx-1.30.5 release.

Security

  • CVE-2026-90439 — fixes a buffer overflow that occurs when using map and regex directives. Remote attackers could trigger a denial-of-service or limited data corruption on systems running nginx 1.29.2 through 1.31.5. Severity: major.

Fixes

  • Buffer overflow addressed in the ngx_http_v3_module (HTTP/3) path, brought in line with the corresponding fix in the stable branch.

Impact

Versions 1.31.6 and 1.30.5 are the patched builds. Administrators running mainline 1.31.x should upgrade immediately to 1.31.6; those on stable should move to 1.30.5. Since this is a targeted security release, no new feature work or configuration changes are introduced.

Other Versions

By continuing to use the site, you agree to the use of cookies.