Security update: Apache httpd 2.4.69 RPM and DEB packages with HTTP/2, HTTP/3, Brotli, TLS 1.3, OpenSSL 4.0.3 and ALPN for EL7/EL8/EL9/EL10, Ubuntu 22.04/24.04

Apache httpd 2.4.69 has been added to the CodeIT repository, built with HTTP/2 (mod_http2), Brotli, TLS 1.3 and ALPN, against OpenSSL 4.0.3. The packages are built for RHEL, CentOS, AlmaLinux, Rocky Linux and Oracle Linux 7, 8, 9 and 10, and for Ubuntu 22.04 and 24.04.

This update fixes security vulnerabilities. Upgrading is recommended.

From 2.4.69 on, mod_ssl is built against the OpenSSL 3.0 API instead of 1.1.1 (OPENSSL_API_COMPAT raised from 1.1.1 to 3.0.0), because OpenSSL 4.0 removes features that were deprecated before 3.0. SRP (TLS-SRP, RFC 5054) goes with it: the SSLSRPVerifierFile and SSLSRPUnknownUserSeed directives no longer exist, so remove them from your configuration before upgrading or httpd will not start, and the SSL_SRP_USER and SSL_SRP_USERINFO variables are no longer set. The ENGINE API was already disabled in these packages.

mod_http2 in the RPM packages is now built from the httpd source tree, the way the DEB packages and Ubuntu’s own apache2 already do, instead of from the separate mod_h2 project. The package keeps its name, mod_http2, and now carries the httpd version, so dnf or yum upgrade from mod_http2 2.0.42 to it on their own: nothing has to be removed first, and an edited 10-h2.conf is kept.

HTTP/3 is available for this httpd through mod_http3, an experimental module packaged separately:

  • RPM, EL8 and later: dnf install mod_http3
  • RPM, EL7: yum install mod_http3
  • DEB: apt install libapache2-mod-http3

The module is loaded as soon as it is installed; HTTP/3 itself is enabled per virtual host. Edit the example vhost the package installs (ServerName and certificate): on EL it is /etc/httpd/vhosts.d/http3-vhost.conf, which httpd.conf does not include by default, so add IncludeOptional vhosts.d/*.conf; on Ubuntu run a2ensite http3-vhost. Then reload httpd and open 443/udp in the firewall, since QUIC runs over UDP.

Major changes:

  • Fix the tar icon in the documentation so that its background is transparent. PR 70238.
  • mod_ssl: Fix OpenSSL compatibility macros for X509_get0_notBefore, X509_get0_notAfter, and X509_get0_serialNumber with OpenSSL < 1.1. PR 70205.
  • mod_cgid, mod_ssl, mod_md: Various hardening fixes.
  • mod_md: MDServerStatus is now disabled by default.
  • mod_auth_digest: Fix compatibility with expression-based AuthName. PR 59039.
  • mod_auth_digest.c: Drop RFC 2069 support; rewrite shared memory handling and client nonce handling; “authdigest-opaque” mutex is now longer needed.
  • mod_lbmethod_heartbeat: Use safe integer parsing with range validation, replacing atoi().
  • core: Reject control characters in the reason phrase of interim responses. Only accept space as status-code separator.
  • mod_substitute: Fix SubstituteMaxLineLength to reject values too large for the K/M/G suffix.
  • mod_substitute: Fix crash or misbehaviour when loading a Substitute directive with a missing closing delimiter.
  • mod_dir: Fix a crash in fixup_dir for a request not mapped to any type. PR68527.
  • mod_http2: Do not drop an in-flight response when a client sends a graceful GOAWAY (error code 0) while streams it opened are still being processed. The session now drains open streams instead of tearing down immediately, which async MPMs hit far more than event. Fixes a silently dropped response; RFC 9113 compliant.
  • mod_md: OpenSSL 4 compatibility.
  • pytest_suite: Port of the old PERL test framework to Python and pytest. Now included in the source tree under ./test

Fixed vulnerabilities:

  • SECURITY: CVE-2026-93546: mod_dav_fs namespace overflow Integer overflow in mod_dav_fs in Apache HTTP Server through 2.4.68 allows an authenticated WebDAV client with write access to crash worker processes and persistently corrupt a directory’s property database via PROPPATCH requests declaring many XML namespaces.
  • SECURITY: CVE-2026-79768: mod_userdir information disclosure Path equivalence: ‘/./’ (single dot directory) vulnerability in Apache HTTP Server’s mod_userdir module when configured with absolute non-wildcard UserDir directive (the 2nd form in) This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
  • SECURITY: CVE-2026-73637: mod_auth_digest DoS attack Use after free in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause authentication state corruption via concurrent Digest authentication requests when AuthDigestNcCheck is enabled or AuthDigestNonceLifetime is set to 0. Users are recommended to upgrade to version 2.4.69, which fixes this issue.
  • SECURITY: CVE-2026-73636: mod_auth_digest one-time-nonce replay attack Authentication bypass by capture-replay in mod_auth_digest in Apache Software Foundation Apache HTTP Server 2.4.x on all platforms allows a man-in-the-middle (MITM) attacker to replay captured digest authentication credentials via crafted requests that trigger garbage collection of the client’s shared memory entry when AuthDigestNonceLifetime is set to 0. Users are recommended to upgrade to version 2.4.69, which fixes this issue.
  • SECURITY: CVE-2026-63718: mod_proxy_uwsgi Transfer-Encoding response smuggling Inconsistent Interpretation of HTTP Requests (‘HTTP Request/Response Smuggling’) response smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi and a crafted uwsgi response with Transfer-Encoding. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.68.
  • SECURITY: CVE-2026-63686: mod_xml2enc crash on charset conversion failure A NULL pointer dereference in mod_xml2enc in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an untrusted backend server to cause a denial of service via a proxied response with a charset whose conversion partially succeeds then fails. Users are recommended to upgrade to version 2.4.69, which fixes this issue.
  • SECURITY: CVE-2026-63292: mod_vhost_alias stack overflow Stack-based buffer overflow in mod_vhost_alias in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows a remote client to cause a denial of service or potentially execute arbitrary code via an HTTP request with a Host header exceeding 8192 bytes when VirtualDocumentRoot uses a hostname format specifier and LimitRequestFieldSize is raised above the default. Users are recommended to upgrade to version 2.4.69, which fixes this issue.
  • SECURITY: CVE-2026-63045: mod_proxy_ftp PASV address handling Improper validation of FTP PASV reply address in mod_proxy_ftp in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows, in forward proxy configurations, an untrusted FTP server to cause the proxy to open a data connection to an arbitrary third-party host via a crafted PASV response. Users are recommended to upgrade to version 2.4.69, which fixes this issue.
  • SECURITY: CVE-2026-59797: mod_ssl SSLRequire allows .htaccess ap_expr file-function Improper Privilege Management vulnerability in Apache HTTP Server’s mod_ssl via SSLRequire and file-related expressions. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
  • SECURITY: CVE-2026-59685: Out-of-Bounds Write in ap_directory_walk() Canonical-Name Rewrite on CASE_BLIND_FILESYSTEM Out-of-bounds Write vulnerability in Apache HTTP Server on Windows while processing paths with 8.3 names that may grow when expanded. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
  • SECURITY: CVE-2026-58415: mod_dav_fs property database read access Internal state files accessible to external parties in mod_dav_fs in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows a remote client to read WebDAV dead properties of resources it cannot author via a GET request for the .DAV state directory This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
  • SECURITY: CVE-2026-57941: mod_http2 use-after-free / wild write via shared session->bbtmp re-entrancy Use After Free vulnerability in Apache HTTP Server’s mod_http2 via shared session->bbtmp re-entrancy This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
  • SECURITY: CVE-2026-56449: mod_proxy_html: crash in dump_content Out-of-bounds Write vulnerability in Apache HTTP Server’s mod_proxy_html with crafted HTTP response bodies. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
  • SECURITY: CVE-2026-56154: mod_rewrite use-after-free via %{LA-U:HTTP…} Use After Free vulnerability in Apache HTTP Server’s mod_rewrite when using lookahead (%{LA-U:HTTP…}) This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
  • SECURITY: CVE-2026-56153: mod_charset_lite: Heap overflow in finish_partial_char Out-of-bounds Write vulnerability in Apache HTTP Server’s mod_charset_lite. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
  • SECURITY: CVE-2026-48005: mod_auth_digest reauthentication attack Missing authentication checks in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause a denial of service (forced re-authentication) via forged Authorization headers when Digest authentication is enabled with AuthDigestNcCheck. Users are recommended to upgrade to version 2.4.69, which fixes this issue.
  • SECURITY: CVE-2026-47360: mod_session: Session cookie not removed during internal redirect Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache HTTP Server’s mod_session_cookie module.
  • SECURITY: CVE-2026-46729: mod_heartmonitor denial of service NULL Pointer Dereference vulnerability in Apache HTTP Servers mod_heartmonitor over unicast listener. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
  • SECURITY: CVE-2026-42528: mod_dav shared lock overflow A memory calculation bug in mod_dav in Apache httpd 2.4.67 and earlier allows an attacker with permission to create WebDAV locks to crash server child processes. Users are recommended to upgrade to version 2.4.69, which fixes this issue
  • SECURITY: CVE-2026-42356: limited RCE for some internal redirects to non-CGI files in CGI directories Deployment of wrong handler vulnerability in Apache HTTP Server allows the target of some internal redirects from CGI programs to also be treated as CGI and executed. The target must already be in a directory enabled for CGI and have no other extension understood by mod_mime. This issue affects Apache HTTP Server: from 2.4.60 through 2.4.68.

Security update: NGINX 1.31.6 Mainline RPM and DEB packages with HTTP/3, Brotli, TLS 1.3 and OpenSSL 4.0.2 for EL7/EL8/EL9/EL10, Ubuntu 22.04/24.04

nginx 1.31.6 Mainline with HTTP/3 support has been added to the CodeIT repository. http2 and ngx_cache_purge are built in, and OpenSSL is linked dynamically against the official OpenSSL 4.0.2 with QUIC support. The Brotli compression module from Google and ngx_http_geoip2 ship as dynamic modules, in nginx-module-brotli and nginx-module-geoip2, which the nginx rpm pulls in automatically (kept as a dependency so that existing installations upgrade without losing those directives; it will be dropped in a few months, and both modules then become truly optional). The packages are built for RHEL, CentOS, AlmaLinux, Rocky Linux and Oracle Linux 7, 8, 9 and 10, and for Ubuntu 22.04 and 24.04.

This update fixes security vulnerabilities. Upgrading is recommended.

More dynamic modules are packaged alongside and are optional: nginx-module-lua with lua-resty-core and lua-resty-lrucache, nginx-module-acme for automatic ACMEv2 certificates, nginx-module-njs, nginx-module-perl, nginx-module-xslt and nginx-module-image-filter. Each one ships its own load_module line in /etc/nginx/modules-enabled, so it works the moment it is installed and nothing has to be added to nginx.conf by hand. Lua and ACME are built for EL9, EL10 and Ubuntu; EL7 gets nginx-module-geoip instead, and njs, Perl, XSLT and image-filter are RPM only.

The same release is on Docker Hub as codeitus/nginx, built on AlmaLinux 9 from these packages and published for amd64 and arm64:

  • the newest image, from whichever pool was released last: docker pull codeitus/nginx
  • the newest Mainline image: docker pull codeitus/nginx:mainline
  • this exact release: docker pull codeitus/nginx:1.31.6

HTTP/3 needs the UDP port published as well as the TCP ones: docker run -d -p 80:80 -p 443:443 -p 443:443/udp codeitus/nginx

Major changes:

  • Change: now the QUIC transport parameters extension received in an SSL connection is always ignored.
  • Bugfix: binary upgrade refused to work if the control API socket was specified and the new nginx executable was built with the ngx_http_perl_module.
  • Bugfix: an error while evaluating a predicate in a predicate location was ignored and the predicate was treated as false.
  • Bugfix: an error during a nested location lookup might be ignored if locations given by regular expressions or predicates were configured at the current level.
  • Bugfix: a segmentation fault might occur while reading configuration if the “geo” directive with the “ranges” parameter was used and the corresponding binary base file was corrupted.

Fixed vulnerabilities:

  • Security: a heap memory buffer overflow might occur in a worker process under certain configurations when using HTTP/3 with OpenSSL 3.5.0 and earlier (CVE-2026-90439).

Security update: NGINX 1.30.5 Stable RPM and DEB packages with HTTP/3, Brotli, TLS 1.3 and OpenSSL 4.0.2 for EL7/EL8/EL9/EL10, Ubuntu 22.04/24.04

nginx 1.30.5 Stable with HTTP/3 support has been added to the CodeIT repository. http2 and ngx_cache_purge are built in, and OpenSSL is linked dynamically against the official OpenSSL 4.0.2 with QUIC support. The Brotli compression module from Google and ngx_http_geoip2 ship as dynamic modules, in nginx-module-brotli and nginx-module-geoip2, which the nginx rpm pulls in automatically (kept as a dependency so that existing installations upgrade without losing those directives; it will be dropped in a few months, and both modules then become truly optional). The packages are built for RHEL, CentOS, AlmaLinux, Rocky Linux and Oracle Linux 7, 8, 9 and 10, and for Ubuntu 22.04 and 24.04.

This update fixes security vulnerabilities. Upgrading is recommended.

More dynamic modules are packaged alongside and are optional: nginx-module-lua with lua-resty-core and lua-resty-lrucache, nginx-module-acme for automatic ACMEv2 certificates, nginx-module-njs, nginx-module-perl, nginx-module-xslt and nginx-module-image-filter. Each one ships its own load_module line in /etc/nginx/modules-enabled, so it works the moment it is installed and nothing has to be added to nginx.conf by hand. Lua and ACME are built for EL9, EL10 and Ubuntu; EL7 gets nginx-module-geoip instead, and njs, Perl, XSLT and image-filter are RPM only.

The same release is on Docker Hub as codeitus/nginx, built on AlmaLinux 9 from these packages and published for amd64 and arm64:

  • the newest image, from whichever pool was released last: docker pull codeitus/nginx
  • the newest Stable image: docker pull codeitus/nginx:stable
  • this exact release: docker pull codeitus/nginx:1.30.5

HTTP/3 needs the UDP port published as well as the TCP ones: docker run -d -p 80:80 -p 443:443 -p 443:443/udp codeitus/nginx

Major changes:

  • Change: now the QUIC transport parameters extension received in an SSL connection is always ignored.

Fixed vulnerabilities:

  • Security: a heap memory buffer overflow might occur in a worker process under certain configurations when using HTTP/3 with OpenSSL 3.5.0 and earlier (CVE-2026-90439).

NGINX 1.31.5 Mainline RPM and DEB packages with HTTP/3, Brotli, TLS 1.3 and OpenSSL 4.0.2 for EL7/EL8/EL9/EL10, Ubuntu 22.04/24.04

nginx 1.31.5 Mainline with HTTP/3 support has been added to the CodeIT repository. http2 and ngx_cache_purge are built in, and OpenSSL is linked dynamically against the official OpenSSL 4.0.2 with QUIC support. The Brotli compression module from Google and ngx_http_geoip2 ship as dynamic modules, in nginx-module-brotli and nginx-module-geoip2, which the nginx rpm pulls in automatically (kept as a dependency so that existing installations upgrade without losing those directives; it will be dropped in a few months, and both modules then become truly optional). The packages are built for RHEL, CentOS, AlmaLinux, Rocky Linux and Oracle Linux 7, 8, 9 and 10, and for Ubuntu 22.04 and 24.04.

More dynamic modules are packaged alongside and are optional: nginx-module-lua with lua-resty-core and lua-resty-lrucache, nginx-module-acme for automatic ACMEv2 certificates, nginx-module-njs, nginx-module-perl, nginx-module-xslt and nginx-module-image-filter. Each one ships its own load_module line in /etc/nginx/modules-enabled, so it works the moment it is installed and nothing has to be added to nginx.conf by hand. Lua and ACME are built for EL9, EL10 and Ubuntu; EL7 gets nginx-module-geoip instead, and njs, Perl, XSLT and image-filter are RPM only.

The same release is on Docker Hub as codeitus/nginx, built on AlmaLinux 9 from these packages and published for amd64 and arm64:

  • the newest image, from whichever pool was released last: docker pull codeitus/nginx
  • the newest Mainline image: docker pull codeitus/nginx:mainline
  • this exact release: docker pull codeitus/nginx:1.31.5

HTTP/3 needs the UDP port published as well as the TCP ones: docker run -d -p 80:80 -p 443:443 -p 443:443/udp codeitus/nginx

Major changes:

  • Feature: control API.
  • Feature: predicate locations.
  • Feature: the ngx_http_json_module.
  • Feature: the “client_body_early_read” directive.
  • Bugfix: use-after-free might occur in a worker process if proxying with buffering was used and an error occurred while sending the response to an HTTP/2 client.
  • Bugfix: a worker process might not exit or “accept4() failed (9: Bad file descriptor)” alerts might appear in logs if the worker process ran out of file descriptors before graceful shutdown.
  • Bugfix: requests to FastCGI and uwsgi backends were malformed if a parameter name was too long.
  • Bugfixes in HTTP/3, ngx_http_slice_module, and ngx_http_memcached_module.

NGINX 1.31.4 Mainline RPM and DEB packages with HTTP/3, Brotli, TLS 1.3 and OpenSSL 4.0.1 for EL7/EL8/EL9/EL10, Ubuntu 22.04/24.04

nginx 1.31.4 Mainline with HTTP/3 support has been added to the CodeIT repository. http2 and ngx_cache_purge are built in, and OpenSSL is linked dynamically against the official OpenSSL 4.0.1 with QUIC support. The Brotli compression module from Google and ngx_http_geoip2 ship as dynamic modules, in nginx-module-brotli and nginx-module-geoip2, which the nginx rpm pulls in automatically (kept as a dependency so that existing installations upgrade without losing those directives; it will be dropped in a few months, and both modules then become truly optional). The packages are built for RHEL, CentOS, AlmaLinux, Rocky Linux and Oracle Linux 7, 8, 9 and 10, and for Ubuntu 22.04 and 24.04.

More dynamic modules are packaged alongside and are optional: nginx-module-lua with lua-resty-core and lua-resty-lrucache, nginx-module-acme for automatic ACMEv2 certificates, nginx-module-njs, nginx-module-perl, nginx-module-xslt and nginx-module-image-filter. Each one ships its own load_module line in /etc/nginx/modules-enabled, so it works the moment it is installed and nothing has to be added to nginx.conf by hand. Lua and ACME are built for EL9, EL10 and Ubuntu; EL7 gets nginx-module-geoip instead, and njs, Perl, XSLT and image-filter are RPM only.

The same release is on Docker Hub as codeitus/nginx, built on AlmaLinux 9 from these packages and published for amd64 and arm64:

  • the newest image, from whichever pool was released last: docker pull codeitus/nginx
  • the newest Mainline image: docker pull codeitus/nginx:mainline
  • this exact release: docker pull codeitus/nginx:1.31.4

HTTP/3 needs the UDP port published as well as the TCP ones: docker run -d -p 80:80 -p 443:443 -p 443:443/udp codeitus/nginx

Major changes:

  • Feature: the “proxy_protocol” directive in the stream and mail modules now supports the PROXY protocol version 2.
  • Change: now HTTP/2 and gRPC requests to backends are always sent with the “:authority” pseudo-header, and HTTP/1.1 requests – with the “Host” header.
  • Bugfix: a segmentation fault might occur in a worker process if the “select” method was used.
  • Bugfix: incomplete gRPC responses with a non-zero “Content-Length” header line are now treated as malformed.
  • Bugfix: in binary compatibility with third-party modules using script codes; the bug had appeared in 1.31.3.
  • Bugfix: in the ngx_http_perl_module.
  • Bugfixes in HTTP/2, HTTP/3, ngx_http_image_filter_module, and ngx_http_grpc_module.

nghttp2 1.70.0 rpms released

nghttp2 1.70.0 rpms released and added to all supported platforms.

Major changes:

Require C++23 by @tatsuhiro-t in #2688 Adopt Designated initializers part1 by @tatsuhiro-t in #2689 Adopt Designated initializers part2 by @tatsuhiro-t in #2690 Adopt Designated initializers part3 by @tatsuhiro-t in #2691 tests: Make const values static const by @tatsuhiro-t in #2692 src: Rewrite util::split_str and its variants by @tatsuhiro-t in #2693 src: Adopt std::string::resize_and_overwrite by @tatsuhiro-t in #2694 src: Pass std::chrono::{time_point,duration} by value by @tatsuhiro-t in #2695 Bump mruby to 4.0.0 by @tatsuhiro-t in #2696 src: Fix warning “space between quotes and suffix is deprecated in C++23” by @tatsuhiro-t in #2697 lib, tests: Use C-style comment by @tatsuhiro-t in #2698 src: Avoid std::chrono::high_resolution_clock by @tatsuhiro-t in #2699 src: Add noexcept to user-defined literals by @tatsuhiro-t in #2700 src: Replace std::optional with std::expected by @tatsuhiro-t in #2701 src/util: Adopt std::expected for error handling by @tatsuhiro-t in #2702 get_socket_error: Return errno of getsockopt if it fails by @tatsuhiro-t in #2703 src: Use util::stream_error by @tatsuhiro-t in #2704 src: Get rid of std::stringstream by @tatsuhiro-t in #2705 src: Modernize Header and HeaderRef by @tatsuhiro-t in #2707 src/http2: Adopt std::expected by @tatsuhiro-t in #2708 src/tls: Adopt std::expected by @tatsuhiro-t in #2709 nghttpx: Adopt std::expected for Connection read/write by @tatsuhiro-t in #2710 Nghttpx dconn expected by @tatsuhiro-t in #2711 Nghttpx downstream expected by @tatsuhiro-t in #2712 Nghttpx http2session expected by @tatsuhiro-t in #2713 Nghttpx upstream expected by @tatsuhiro-t in #2714 Nghttpx clienthandler expected by @tatsuhiro-t in #2715 Nghttpx httpdownstreamconnection expected by @tatsuhiro-t in #2716 Nghttpx expected by @tatsuhiro-t in #2717 Nghttpx http2upstream expected by @tatsuhiro-t in #2718 Nghttpx http3upstream expected by @tatsuhiro-t in #2719 Nghttpx mruby expected by @tatsuhiro-t in #2720 Nghttpx quic expected by @tatsuhiro-t in #2721 nghttpx: Adopt std::expected for QUICConnectionHandler by @tatsuhiro-t in #2722 Nghttpx tls expected by @tatsuhiro-t in #2723 nghttpx: Rewrite time_t_from_asn1_time with ASN1_TIME_diff for boringssl by @tatsuhiro-t in #2724 Nghttpx livecheck expected by @tatsuhiro-t in #2725 Nghttpx dns expected by @tatsuhiro-t in #2726 Nghttpx memcached expected by @tatsuhiro-t in #2727 Nghttpx misc expected by @tatsuhiro-t in #2728 Nghttpx worker expected by @tatsuhiro-t in #2729 Nghttpx connhandler expected by @tatsuhiro-t in #2730 nghttpx: Pass WorkerEvent without explicit std::move by @tatsuhiro-t in #2731 nghttpx: Adopt std::expected for worker_process_event_loop by @tatsuhiro-t in #2732 nghttpx: Adopt std::expected for parse_config by @tatsuhiro-t in #2733 Nghttpx config expected by @tatsuhiro-t in #2734 Src fixup by @tatsuhiro-t in #2735 nghttpx: Adopt std::expected for main routines by @tatsuhiro-t in #2736 H2load expected by @tatsuhiro-t in #2737 nghttp: Adopt std::expected by @tatsuhiro-t in #2738 nghttpd: Adopt std::expected by @tatsuhiro-t in #2739 HtmlParser: Adopt std::expected by @tatsuhiro-t in #2740 src: Adopt size_t literal suffix by @tatsuhiro-t in #2742 nghttp: put pseudo headers before normal headers by @zhanhb in #2741 h2load: Replace std::cerr with std::print by @tatsuhiro-t in #2744 h2load: Replace std::cout with std::print by @tatsuhiro-t in #2745 nghttpx: Migrate to std::print by @tatsuhiro-t in #2746 Nghttp print by @tatsuhiro-t in #2747 Nghttpd print by @tatsuhiro-t in #2748 src: Migrate std::cout to std::print by @tatsuhiro-t in #2749 src: Simplify as_string_view usage by @tatsuhiro-t in #2750 src: Migrate fprintf to C++ counterparts by @tatsuhiro-t in #2751 src: Use std::println without argument to print just line separator by @tatsuhiro-t in #2752 nghttpx: Create CID encryption ctx per worker by @tatsuhiro-t in #2753 nghttpx: Use std::unique_ptr for quic_keying_materials_ by @tatsuhiro-t in #2754 Src optimize by @tatsuhiro-t in #2755 src: Provide faster hash functions for OpenSSL forks by @tatsuhiro-t in #2756 src: Adopt std::expected for http2::make_websocket_accept_token by @tatsuhiro-t in #2757 src: NSDMI part1 by @tatsuhiro-t in #2758 src: Add noexcept to move ctor and assignment operator by @tatsuhiro-t in #2759 build(deps): bump github.com/quic-go/quic-go from 0.59.0 to 0.59.1 by @dependabot[bot] in #2760 build(deps): bump golang.org/x/net from 0.53.0 to 0.54.0 by @dependabot[bot] in #2761 src: MSDMI part2 by @tatsuhiro-t in #2762 Avoid azure ubuntu mirror by @tatsuhiro-t in #2763 src: MSDMI part3 by @tatsuhiro-t in #2764 src/allocator: Rewrite concat_string_ref with fold expression by @tatsuhiro-t in #2765 src: Fix build failure on macos26 by @tatsuhiro-t in #2766 cmake: Remove CMAKE_CXX_STANDARD 23 that is not needed there by @tatsuhiro-t in #2767 Fix base64 oob by @tatsuhiro-t in #2768 Nghttpx upgrade by @tatsuhiro-t in #2769 Make NGHTTP2_HTTP_FLAG_* macros and make them unsigned by @tatsuhiro-t in #2770 Define flags as macros by @tatsuhiro-t in #2771 Make NGHTTP2_EXTPRI_INC_MASK unsigned by @tatsuhiro-t in #2772 src: Avoid zero-argument std::println by @kmehltretter82 in #2773 build(deps): bump golang.org/x/net from 0.54.0 to 0.55.0 by @dependabot[bot] in #2774 GHA: Add Cygwin build by @tatsuhiro-t in #2775 Fix docker build by @tatsuhiro-t in #2776 lib: Rewrite integer decoder in http by @tatsuhiro-t in #2777 Bump ngtcp2 and its dependencies by @tatsuhiro-t in #2778 Avoid deprecated ngtcp2 and nghttp3 apis by @tatsuhiro-t in #2779 net: Use macros for win32 hton*/ntoh* fallbacks by @tatsuhiro-t in #2780 lib: Add nghttp2_downcase_byte by @tatsuhiro-t in #2781 Rework HTTP header validation by @tatsuhiro-t in #2782 Bump sfparse by @tatsuhiro-t in #2783 helper: Initialize array with designated initializers by @tatsuhiro-t in #2784 Reformat downcase table by @tatsuhiro-t in #2785 http: Initialize array with designated initializers by @tatsuhiro-t in #2786 Upper case hex integer literals in huffman data table by @tatsuhiro-t in #2787 Upcase hex by @tatsuhiro-t in #2788 Nghttpx h2 stream write timeout by @tatsuhiro-t in #2789 bpf, examples, tests: Upper case hex integer literals by @tatsuhiro-t in #2790 Reformat huffman data table by @tatsuhiro-t in #2791 nghttpx: Provide frontend and backend stream timeouts by @tatsuhiro-t in #2794 build(deps): bump github.com/quic-go/quic-go from 0.59.1 to 0.60.0 by @dependabot[bot] in #2792 nghttpx: Reformat help message to make it editor friendly by @tatsuhiro-t in #2796 nghttpx: Drop connection when frontend write rate is too low by @tatsuhiro-t in #2797 build(deps): bump golang.org/x/net from 0.55.0 to 0.56.0 by @dependabot[bot] in #2799 build(deps): bump actions/checkout from 6 to 7 by @dependabot[bot] in #2800 Bump ngtcp2 and its dependencies by @tatsuhiro-t in #2802 nghttpx: Drop h3 connection when frontend write rate is too low by @tatsuhiro-t in #2803 build(deps): bump actions/cache from 5 to 6 by @dependabot[bot] in #2804 Gcc 16 by @tatsuhiro-t in #2805 nghttpx: NGHTTP2_ERR_TEMPORAL_CALLBACK_FAILURE is not allowed in on_frame_recv_callback by @tatsuhiro-t in #2806 nghttpx: Rename completeCb_ to complete_cb_ by @tatsuhiro-t in #2807 nghttpx: Remove unused unordered_set include by @tatsuhiro-t in #2808 Require nghttp3 >= 1.17.0 by @tatsuhiro-t in #2810 Add the missing header value check for priority header field by @tatsuhiro-t in #2813 build(deps): bump golang.org/x/net from 0.56.0 to 0.57.0 by @dependabot[bot] in #2814 build(deps): bump actions/setup-go from 6 to 7 by @dependabot[bot] in #2815 Count CONTINUATIONS per its frame header by @tatsuhiro-t in #2818 build(deps): bump github.com/quic-go/quic-go from 0.60.0 to 0.61.0 by @dependabot[bot] in #2819 Bump ngtcp2 and its dependencies by @tatsuhiro-t in #2820 Bump neverbleed by @tatsuhiro-t in #2821 Bump llhttp to v9.4.2 by @tatsuhiro-t in #2822 nghttpx: Reset quic upstream addr fd to the current path by @tatsuhiro-t in #2823

NGINX 1.31.3 Mainline with Brotli, TLS 1.3, OpenSSL 4.0.1, HTTP/2 and HTTP/3 for Red Hat Enterprise Linux, CentOS, Rocky, Oracle, Alma Linux EL7/EL8/EL9/EL10

nginx 1.31.3 Mainline with HTTP/3 support added to EL7, EL8, EL9 and EL10 repositories. Brotli compression module from Google, http2, ngx_cache_purge and ngx_http_geoip2 modules are built in. OpenSSL is built dynamically using official OpenSSL 4.0.1 with QUIC support.

Major changes:

*) Security: heap buffer overflow might occur in a worker process when using the map directive with regex matching if the map variable was included in a string expression after a capture affected by this map; a similar issue might happen when using a non-cacheable variable in a string expression (CVE-2026-42533). Thanks to Mufeed VH of Winfunc Research and Maxim Dounin.

*) Security: uninitialized memory access might occur when using unnamed regex captures with the “slice” directive or background cache update, which could result in worker process memory disclosure or worker process termination (CVE-2026-60005).

*) Security: use-after-free might occur when processing a specially crafted proxied backend response with the ngx_http_ssi_filter_module (CVE-2026-56434). Thanks to P4P3R-HAK.

*) Change: the size of headers and trailers in HTTP/2 responses in the ngx_http_proxy_v2_module and ngx_http_grpc_module is now limited with “proxy_buffer_size” and “grpc_buffer_size” directives.

*) Change: loading of external entities is now disabled in the ngx_http_xslt_filter_module. Thanks to Maxim Dounin.

*) Feature: the “xml_external_entities” directive in the ngx_http_xslt_filter_module. Thanks to Maxim Dounin.

*) Feature: the “proxy_socket_sndbuf”, “proxy_socket_rcvbuf”, “fastcgi_socket_sndbuf”, “fastcgi_socket_rcvbuf”, “grpc_socket_sndbuf”, “grpc_socket_rcvbuf”, “scgi_socket_sndbuf”, “scgi_socket_rcvbuf”, “uwsgi_socket_sndbuf”, “uwsgi_socket_rcvbuf”, “tunnel_socket_sndbuf”, and “tunnel_socket_rcvbuf” directives.

*) Feature: cache line size detection for loongarch64. Thanks to Miao Wang.

*) Bugfix: now nginx rejects HTTP/2 requests with out-of-order pseudo-headers.

*) Bugfix: in flow control in the ngx_http_v2_module.

*) Bugfix: “[error] upstream sent frame for unknown stream” and “[crit] cache file … contains invalid header” messages might appear in logs when sending a cached HTTP/2 response in the ngx_http_proxy_v2_module if the “proxy_cache_revalidate” directive was used.

*) Bugfix: nginx might send the “Upgrade” header line in HTTP/2 and HTTP/3 responses.

*) Bugfix: in the ngx_http_perl_module. Thanks to Maxim Dounin.

*) Bugfix: IPv6 fragmentation might not be disabled when using QUIC on some operating systems.

*) Bugfix: in the ngx_http_auth_basic_module on Solaris.

*) Bugfixes and improvements in the ngx_http_tunnel_module.

NGINX 1.30.4 Stable with Brotli, TLS 1.3, OpenSSL 4.0.1, HTTP/2 and HTTP/3 for Red Hat Enterprise Linux, CentOS, Rocky, Oracle, Alma Linux EL7/EL8/EL9/EL10

nginx 1.30.4 Stable with HTTP/3 support added to EL7, EL8, EL9 and EL10 repositories. Brotli compression module from Google, http2, ngx_cache_purge and ngx_http_geoip2 modules are built in. OpenSSL is built dynamically using official OpenSSL 4.0.1 with QUIC support.

Major changes:

    *) Security: heap buffer overflow might occur in a worker process when using the map directive with regex matching if the map variable was included in a string expression after a capture affected by this map; 
       a similar issue might happen when using a non-cacheable variable in a string expression (CVE-2026-42533).
       Thanks to Mufeed VH of Winfunc Research and Maxim Dounin.

    *) Security: uninitialized memory access might occur when using unnamed regex captures with the "slice" directive or background cache update, which could result in worker process memory disclosure or worker process termination (CVE-2026-60005).

    *) Security: use-after-free might occur when processing a specially crafted proxied backend response with the ngx_http_ssi_filter_module (CVE-2026-56434).
       Thanks to P4P3R-HAK.

NGINX 1.30.3 Stable with Brotli, TLS 1.3, OpenSSL 4.0.1, HTTP/2 and HTTP/3 for Red Hat Enterprise Linux, CentOS, Rocky, Oracle, Alma Linux EL7/EL8/EL9/EL10

nginx 1.30.3 Stable with fixes for buffer overflow vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module (CVE-2026-42055), and buffer overread vulnerability in the ngx_http_charset_module (CVE-2026-48142)  added to EL7, EL8, EL9 and EL10 repositories. Brotli compression module from Google, http2, ngx_cache_purge and ngx_http_geoip2 modules are built in. OpenSSL is built dynamically using official OpenSSL 4.0.1 with QUIC support.

Major changes:

  • Security: a heap memory buffer overflow might occur in a worker
  • Security: a heap memory buffer overread might occur in a worker

NGINX 1.31.2 Mainline with Brotli, TLS 1.3, OpenSSL 4.0.1, HTTP/2 and HTTP/3 for Red Hat Enterprise Linux, CentOS, Rocky, Oracle, Alma Linux EL7/EL8/EL9/EL10

nginx 1.31.2 Mainline with fixes for buffer overflow vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module (CVE-2026-42055), and buffer overread vulnerability in the ngx_http_charset_module (CVE-2026-48142) added to EL7, EL8, EL9 and EL10 repositories. Brotli compression module from Google, http2, ngx_cache_purge and ngx_http_geoip2 modules are built in. OpenSSL is built dynamically using official OpenSSL 4.0.1 with QUIC support.

Major changes:

  • Security: use-after-free might occur when using HTTP/3 and processing
  • Security: a heap memory buffer overflow might occur in a worker
  • Security: a heap memory buffer overread might occur in a worker
  • Change: now the $request_id variable uses SipHash-2-4.
  • Feature: the $ssl_sigalgs variable.
  • Bugfix: a variable defined by the “split_clients” directive might be constant time “secure_link” hash comparison.