Zum Inhalt springen

28 Einträge aus 1 Quelle. Zuletzt aktualisiert:

Folge F5, um die Release Notes in deinen Feed zu holen.

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Nginx Plus von F5

NGINX Plus PLS.37.0.6.2 LTS: Fix für HTTP/3-Sicherheitslücke

NGINX Plus PLS.37.0.6.2 LTS (basierend auf NGINX Open Source 1.29.8) behebt eine Sicherheitslücke im Modul ngx_http_v3_module, bei der mit HTTP/3 und OpenSSL 3.5.0 oder früher beim TLS-Handshake ein begrenzter Heap-Buffer-Overflow auftreten kann (CVE-2026-90439).

September 15, 2026
Based on NGINX Open Source 1.29.8

NGINX Plus PLS.37.0.6.2 LTS is a security release.

  • Security fix in the ngx_http_v3_module module: when using HTTP/3 with OpenSSL versions 3.5.0 and earlier, a limited heap buffer overflow may occur during TLS handshake processing under certain configurations. The condition is non-deterministic and beyond an attacker’s control. This may cause a heap buffer overflow in the NGINX worker process, potentially resulting in restart and/or limited data corruption. (CVE-2026-90439).

Before upgrading from NGINX Plus R36, review the Upgrade Notes for breaking changes.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Nginx Plus von F5

NGINX Plus PLS.37.1.1.2 CR: Fix für HTTP/3-Sicherheitslücke

NGINX Plus PLS.37.1.1.2 CR (basierend auf NGINX Open Source 1.31.3) behebt eine Sicherheitslücke im Modul ngx_http_v3_module, bei der mit HTTP/3 und OpenSSL 3.5.0 oder früher beim TLS-Handshake ein begrenzter Heap-Buffer-Overflow auftreten kann (CVE-2026-90439).

September 15, 2026
Based on NGINX Open Source 1.31.3

NGINX Plus PLS.37.1.1.2 CR is a security release.

  • Security fix in the ngx_http_v3_module module: when using HTTP/3 with OpenSSL versions 3.5.0 and earlier, a limited heap buffer overflow may occur during TLS handshake processing under certain configurations. The condition is non-deterministic and beyond an attacker’s control. This may cause a heap buffer overflow in the NGINX worker process, potentially resulting in restart and/or limited data corruption. (CVE-2026-90439).

Before upgrading from NGINX Plus R36, review the Upgrade Notes for breaking changes.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Nginx Plus von F5

NGINX Plus PLS.37.0.5.1 LTS: Bugfix-Release

NGINX Plus PLS.37.0.5.1 LTS ist ein Bugfix-Release, und allen Nutzern des LTS-Zweigs wird das Upgrade auf die neueste LTS-Version empfohlen.

September 2, 2026
Based on NGINX Open Source 1.29.8

NGINX Plus PLS.37.0.5.1 LTS is a bugfix release. We recommend that all users on the LTS track upgrade to the latest LTS release to ensure they are running the most stable and secure version of NGINX Plus.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Nginx Plus von F5

NGINX Plus PLS.37.1.0.1 CR: Neue Features für Lizenz, Rate Limiting, TLS

NGINX Plus PLS.37.1.0.1 CR ist ein Feature-Release mit verzögerter Lizenz-Autorenewal über license_pending_token, variablenbasiertem Rate Limiting, neuen SSL/TLS-Funktionen wie proxy_ssl_alpn für Stream und $ssl_sigalgs sowie verbesserter HTTP/2- und HTTP/3-Validierung.

September 2, 2026
Based on NGINX Open Source 1.31.3

NGINX Plus PLS.37.1.0.1 CR is a feature release.

  • Deferred license autorenewal: the license_pending_token directive which allows adding a license via the API. API v10 now supports adding a license with the PUT method.

  • Variable-based rate limiting allowing rate limits to be configured dynamically based on variables.

  • SSL and TLS

    • The proxy_ssl_alpn directive for stream.

    • The $ssl_sigalgs variable that returns the signature algorithm for the server certificate for an established SSL connection.

    • Lowered the logging level of some SSL alert and record-layer errors from crit to info.

  • HTTP/2, HTTP/3, QUIC, and gRPC

    • Improved HTTP/2 and HTTP/3 protocol validation, including stricter handling of connection-related headers, pseudo-headers, and invalid response metadata.

    • Fixed multiple HTTP/2 proxying issues related to flow control, backend connection caching, cached responses, and incorrect Upgrade headers. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Nginx Plus von F5

NGINX Plus PLS.37.0.4.1 LTS: Host-Header und Modulkompatibilität

NGINX Plus PLS.37.0.4.1 LTS verwendet bei einem leeren, per proxy_set_header gesetzten Host-Header jetzt den Wert von $proxy_host und stellt die Kompatibilität mit einigen Drittanbieter-Modulen wie Set-Misc und Lua wieder her.

July 22, 2026
Based on NGINX Open Source 1.29.8

NGINX Plus PLS.37.0.4.1 LTS is a bugfix release:

  • If the Host header field value set by proxy_set_header evaluates to an empty string, the value of $proxy_host is used instead. This prevents sending upstream requests without a Host (HTTP/1.1) or :authority (HTTP/2) header, and also allows health checks to pass in some configurations. The bug appeared in NGINX Plus PLS.37.0.0.1 LTS.

  • Restored compatibility with some third-party dynamic modules available in our repository, for example, Set-Misc and Lua. The bug appeared in NGINX Plus PLS.37.0.3.1 LTS.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Nginx Plus von F5

NGINX Plus R36 P8: Modulkompatibilität und keepalive 0

NGINX Plus R36 P8 stellt die Kompatibilität mit einigen Drittanbieter-Modulen wie Set-Misc und Lua wieder her, und die keepalive-Direktive akzeptiert nun den Wert 0, was das Upgrade auf NGINX Plus PLS.37 LTS erleichtert.

July 22, 2026

This is an improvement release for NGINX Plus R36.

  • Restored compatibility with some third-party dynamic modules available in our repository, for example, Set-Misc and Lua. The bug appeared in NGINX Plus R36 P7.

  • The keepalive directive now accepts the 0 value, making upgrade to NGINX Plus PLS.37 LTS smoother, where HTTP 1.1 and keepalive to upstreams are enabled by default. See this blog post for details.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Nginx Plus von F5

NGINX Plus PLS.37.0.3.1 LTS: Sicherheits-Release mit CVE-Fixes

NGINX Plus PLS.37.0.3.1 LTS ist ein Sicherheits-Release, das unter anderem eine Schwachstelle im ngx_http_ssi_module (CVE-2026-56434) und eine Heap-Buffer-Overflow-Lücke im Zusammenhang mit map-Direktiven mit Regex (CVE-2026-42533) behebt.

July 15, 2026
Based on NGINX Open Source 1.29.8

NGINX Plus PLS.37.0.3.1 LTS is a security release.

  • Security fix in the ngx_http_ssi_module module: when ssi and proxy_pass with disabled buffering (off) directives are configured, an unauthenticated attacker with man-in-the-middle (MITM) ability to control responses from an upstream server may be able to cause a heap buffer over-read in the NGINX worker process, leading to limited modification of memory or a restart (CVE-2026-56434).

  • Security fix: when the map directive with regex matching is configured and the map variable is included in a string expression following the captures affected by this map. Alternatively, the same result could be achieved by using a non-cacheable variable in a string expression under certain conditions. An unauthenticated attacker along with conditions beyond their control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR ([CV…

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Nginx Plus von F5

NGINX Plus R36 P7: Sicherheits-Release mit CVE-Fixes

NGINX Plus R36 P7 ist ein Sicherheits-Release, das unter anderem eine Schwachstelle im ngx_http_ssi_module (CVE-2026-56434) und eine Heap-Buffer-Overflow-Lücke im Zusammenhang mit map-Direktiven mit Regex (CVE-2026-42533) behebt.

July 15, 2026

This is a security release for NGINX Plus R36.

  • Security fix in the ngx_http_ssi_module module: when ssi and proxy_pass with disabled buffering (off) directives are configured, an unauthenticated attacker with man-in-the-middle (MITM) ability to control responses from an upstream server may be able to cause a heap buffer over-read in the NGINX worker process, leading to limited modification of memory or a restart (CVE-2026-56434).

  • Security fix: when the map directive with regex matching is configured and the map variable is included in a string expression following the captures affected by this map. Alternatively, the same result could be achieved by using a non-cacheable variable in a string expression under certain conditions. An unauthenticated attacker along with conditions beyond their control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR ([CVE-2026-42533](https://my.f5.com/manage/s/a…

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Nginx Plus von F5

NGINX Plus PLS.37.0.2.1 LTS: Sicherheitsupdate

NGINX Plus PLS.37.0.2.1 LTS basiert auf NGINX Open Source 1.29.8 und behebt Sicherheitslücken, darunter einen Heap Buffer Over-read im ngx_http_charset_module (CVE-2026-48142) sowie ein Problem beim HTTP/2-Proxying in den Modulen ngx_http_proxy_v2_module und ngx_http_grpc_module.

June 17, 2026
Based on NGINX Open Source 1.29.8

NGINX Plus PLS.37.0.2.1 LTS is a security release.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Nginx Plus von F5

NGINX Plus R36 P6: Sicherheitsfixes für Charset und HTTP/2

NGINX Plus R36 P6 behebt einen Heap Buffer Over-read im ngx_http_charset_module (CVE-2026-48142) sowie eine Sicherheitslücke beim HTTP/2-Proxying in den Modulen ngx_http_proxy_v2_module und ngx_http_grpc_module.

June 17, 2026

This is a security release for NGINX Plus R36.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Nginx Plus von F5

NGINX Plus PLS.37.0.1.1 LTS: Sicherheitsfix im Rewrite-Modul

NGINX Plus PLS.37.0.1.1 LTS behebt einen möglichen Buffer Overflow im ngx_http_rewrite_module bei Ersetzungsstrings ohne Variablen, aber mit überlappenden Captures (CVE-2026-9256).

May 22, 2026
Based on NGINX Open Source 1.29.8

NGINX Plus PLS.37.0.1.1 LTS is a security release.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Nginx Plus von F5

NGINX Plus R36 P5: Sicherheitsfix im Rewrite-Modul

NGINX Plus R36 P5 behebt einen möglichen Buffer Overflow im ngx_http_rewrite_module bei Ersetzungsstrings ohne Variablen, aber mit überlappenden Captures (CVE-2026-9256).

May 22, 2026

This is a security release for NGINX Plus R36.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Nginx Plus von F5

NGINX Plus PLS.37.0.0.1 LTS: erste LTS-Version

NGINX Plus PLS.37.0.0.1 LTS ist die erste LTS-Version auf Basis von NGINX Open Source 1.29.8 und bringt ein neues Release-Modell (LTS und Continuous Releases), ein Agentic-observability-Modul für MCP-Traffic, eine NGINX control REST API, JSON-formatierte Error-Logs, die Direktive error_log_tag und Upstream-Latenz-Histogramme.

May 13, 2026
Based on NGINX Open Source 1.29.8

NGINX Plus PLS.37.0.0.1 LTS is the first LTS release. For more details on the release tracks, release numbering, schedule, and upgrade strategy, see the Introduction section.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Nginx Plus von F5

NGINX Plus R36 P4: mehrere Sicherheitsfixes

NGINX Plus R36 P4 behebt mehrere Sicherheitslücken, darunter einen Heap Buffer Overflow im ngx_http_rewrite_module (CVE-2026-42945) sowie Heap-Overreads in den Modulen ngx_http_scgi_module, ngx_http_uwsgi_module und ngx_http_charset_module.

May 13, 2026

This is a security release for NGINX Plus R36.

  • Security fix in the ngx_http_rewrite_module module: a heap memory buffer overflow might occur in a worker process while handling a specially crafted request by the module, potentially resulting in arbitrary code execution (CVE-2026-42945).

  • Security fix in the ngx_http_scgi_module and ngx_http_uwsgi_module modules: a heap memory buffer overread might occur in a worker process while handling a specially crafted response by these modules, allowing an attacker to cause a disclosure of worker process memory or segmentation fault in a worker process (CVE-2026-42946).

  • Security fix in the ngx_http_charset_module module: a heap memory buffer overread might occur in a worker process while handling a specially crafted response with decoding from UTF-8 via the charset_map directive, allowing an attacker to cause a limited disclosure of worker process memory or segmentation fault in a worker process (CVE-2026-42934). …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Nginx Plus von F5

NGINX Plus R36 P3: mehrere Sicherheitsfixes

NGINX Plus R36 P3 behebt Sicherheitslücken in den Modulen ngx_http_dav_module, ngx_http_mp4_module, ngx_mail_auth_http_module und ngx_mail_smtp_module (u. a. CVE-2026-27654, CVE-2026-32647, CVE-2026-27651, CVE-2026-28753).

March 24, 2026

This is a security release for NGINX Plus R36.

  • Security fix in the ngx_http_dav_module module: a buffer overflow might occur while handling a COPY or MOVE request in a location with alias, allowing an attacker to modify the source or destination path outside of the document root (CVE-2026-27654).

  • Security fix in the ngx_http_mp4_module module: processing of a specially crafted mp4 file might cause a worker process crash, or might have potential other impact (CVE-2026-32647).

  • Security fix in the ngx_mail_auth_http_module module: a segmentation fault might occur in a worker process if the CRAM-MD5 or APOP authentication methods were used and authentication retry was enabled (CVE-2026-27651).

  • Security fix in the ngx_mail_smtp_module module: an attacker might use PTR DNS records to inject data in auth_http requests, as well as in the XCLIENT command in the backend SMTP connection (CVE-2026-28753). …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Nginx Plus von F5

NGINX Plus R35 P2: mehrere Sicherheitsfixes

NGINX Plus R35 P2 behebt Sicherheitslücken in den Modulen ngx_http_dav_module, ngx_http_mp4_module, ngx_mail_auth_http_module und ngx_mail_smtp_module (u. a. CVE-2026-27654, CVE-2026-32647, CVE-2026-27651, CVE-2026-28753).

March 24, 2026

This is a security release for NGINX Plus R35.

  • Security Fix in the ngx_http_dav_module module: a buffer overflow might occur while handling a COPY or MOVE request in a location with alias, allowing an attacker to modify the source or destination path outside of the document root (CVE-2026-27654).

  • Security Fix in the ngx_http_mp4_module module: processing of a specially crafted mp4 file might cause a worker process crash, or might have potential other impact (CVE-2026-32647).

  • Security Fix in the ngx_mail_auth_http_module module: a segmentation fault might occur in a worker process if the CRAM-MD5 or APOP authentication methods were used and authentication retry was enabled (CVE-2026-27651).

  • Security Fix in the ngx_mail_smtp_module module: an attacker might use PTR DNS records to inject data in auth_http requests, as well as in the XCLIENT command in the backend SMTP connection (CVE-2026-28753). …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Nginx Plus von F5

NGINX Plus R36 P2: Sicherheitsfix für Upstream-TLS

NGINX Plus R36 P2 behebt eine Sicherheitslücke, durch die ein Man-in-the-Middle-Angreifer beim Proxying zu Upstream-TLS-Servern Klartextdaten in die Antwort einschleusen könnte (CVE-2026-1642).

February 4, 2026

This is a security release for NGINX Plus R36.

  • Security fix: when proxying to upstream TLS servers, an attacker with Man-in-the-Middle position on the upstream server side along with conditions beyond the attackers control may be able to inject plain text data to the response from an upstream server (CVE-2026-1642).

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Nginx Plus von F5

NGINX Plus R35 P1: Sicherheitsfix für Upstream-TLS

NGINX Plus R35 P1 behebt eine Sicherheitslücke, durch die ein Man-in-the-Middle-Angreifer beim Proxying zu Upstream-TLS-Servern Klartextdaten in die Antwort einschleusen könnte (CVE-2026-1642).

February 4, 2026

This is a security release for NGINX Plus R35.

  • Security Fix: when proxying to upstream TLS servers, an attacker with Man-in-the-Middle position on the upstream server side along with conditions beyond the attackers control may be able to inject plain text data to the response from an upstream server (CVE-2026-1642).

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Nginx Plus von F5

NGINX Plus R36 P1: Absturz bei HTTP/3 behoben

NGINX Plus R36 P1 behebt einen möglichen Absturz bei HTTP/3 in Verbindung mit OpenSSL 3.5.1 oder neuer.

18 December 2025

This is a bugfix release for NGINX Plus R36.

  • HTTP/3: fixed a potential crash when using OpenSSL 3.5.1 or newer.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Nginx Plus von F5

NGINX Plus Release 36 (R36)

NGINX Plus R36 basiert auf NGINX Open Source 1.29.3 und bringt unter anderem einen HTTP-CONNECT-Forward-Proxy, erweiterte native OIDC-Unterstützung (PKCE, Front-Channel-Logout, POST-Client-Authentifizierung), ACME-Erweiterungen, das num_map-Modul und die Variable $upstream_last_addr.

December 1, 2025
Based on NGINX Open Source 1.29.3

NGINX Plus R36 is a feature release:

Originalquelle(öffnet in neuem Tab)Problem melden