Hello! On Wed, Jul 22, 2026 at 03:24:05PM -0700, Derek Shiell via nginx wrote:
> Hello, > > Has FreeNGINX assessed the following NGINX security issues, and do > they affect the current FreeNGINX release? > > - CVE-2026-42533 — regex captures and map > - CVE-2026-60005 — ngx_http_slice_module > - CVE-2026-56434 — ngx_http_ssi_module > > Our downstream build is based on FreeNGINX 1.31.1 and enable and > configure the slice module, so CVE-2026-60005 is particularly > relevant. > > Are fixes planned for a FreeNGINX point release? If so, is there an > expected version or timeline? > Otherwise, are there recommended commits for downstreams to backport? > > References: > - https://nvd.nist.gov/vuln/detail/CVE-2026-42533 > - https://nvd.nist.gov/vuln/detail/CVE-2026-60005 > - https://nvd.nist.gov/vuln/detail/CVE-2026-56434 CVE-2026-42533 (regex captures and map) is a bug (a well-known one, actually), which was mitigated in freenginx 1.31.3 (and the real fix is expected in freenginx 1.31.4, patches are already in the nginx-devel@ mailing list). See here for additional details: https://github.com/freenginx/nginx/issues/27 The mitigation patches were imported by F5 with the claim that it's a "major" security vulnerability. However, this bug requires a specially crafted configuration, which is mostly meaningless and cannot be reasonably used without noticing the bug. By no means it is a security vulnerability. CVE-2026-60005 (ngx_http_slice_module) is a bug which affects subrequests created by the slice module, yet it also requires a quite special configuration (and I very much doubt such a configuration can be reasonably used without noticing the issue). See this commit for more details: https://github.com/nginx/nginx/commit/0cca8e055a2d909f1a00c2071665b502ec2fe94c CVE-2026-56434 (ngx_http_ssi_module) is a bug in SSI handling which can cause duplicate subrequest finalization with certain timing conditions, yet it can only by triggered by your own backend server. Not sure about "limited modification of memory" which F5 advisory claims as I haven't looked into details yet, but the DoS impact is certainly meaningless as it is implied by SSI and backend control required to trigger the bug. See this commit for more details: https://github.com/nginx/nginx/commit/700dc9e0e750e3f63587f9d0f9f36bae5ec47202 Summing the above, none of the issues looks like a security vulnerability to me. Hope this helps. -- Maxim Dounin http://mdounin.ru/
