Skip to content

nginx: Vulnerable to CVE-2026-42945 #29480

Description

@mali1

Package Name

nginx

Maintainer

Thomas Heil heil@terminal-consulting.de Christian Marangi ansuelsmth@gmail.com

OpenWrt Version

25.12.4

OpenWrt Target/Subtarget

ramips/mt7621, all

Steps to Reproduce

Install nginx-full via apk

Actual Behaviour

Hi,
at the moment the provided package for nginx has the version 1.26.3-r3. Unfortunately it is vulnerable to CVE-2026-42945 and also no longer receives security patches.
The current version would be 1.31 which is not vulnerable https://nginx.org/en/security_advisories.html .
Is there a chance to get this package updated in the official repositories?

Confirmation Checklist

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions