Skip to content

nginx: Vulnerable to CVE-2026-42945 #29480

@mali1

Description

@mali1

Package Name

nginx

Maintainer

Thomas Heil heil@terminal-consulting.de Christian Marangi ansuelsmth@gmail.com

OpenWrt Version

25.12.4

OpenWrt Target/Subtarget

ramips/mt7621, all

Steps to Reproduce

Install nginx-full via apk

Actual Behaviour

Hi,
at the moment the provided package for nginx has the version 1.26.3-r3. Unfortunately it is vulnerable to CVE-2026-42945 and also no longer receives security patches.
The current version would be 1.31 which is not vulnerable https://nginx.org/en/security_advisories.html .
Is there a chance to get this package updated in the official repositories?

Confirmation Checklist

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions