This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+11 more
Affected surfaces
ReleasePort's take
Moderate signalThe release updates nginx to version 1.30.2, which patches CVE‑2026‑9256, a heap buffer overflow vulnerability.
Why it matters: CVE‑2026‑9256 has severity score 95; upgrading nginx to 1.30.2 eliminates the vulnerability for any component relying on the nginx dependency.
Summary
AI summaryUpdates All-in-one, BunkerWeb, and Scheduler across a mixed release.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Critical |
Updates nginx to 1.30.2, fixing CVE-2026-9256 heap buffer overflow vulnerability. Updates nginx to 1.30.2, fixing CVE-2026-9256 heap buffer overflow vulnerability. Source: llm_adapter@2026-05-25 Confidence: high |
— |
Full changelog
Documentation : https://docs.bunkerweb.io/1.6.11/
Docker tags :
- All-in-one :
bunkerity/bunkerweb-all-in-one:1.6.11orghcr.io/bunkerity/bunkerweb-all-in-one:1.6.11 - BunkerWeb :
bunkerity/bunkerweb:1.6.11orghcr.io/bunkerity/bunkerweb:1.6.11 - Scheduler :
bunkerity/bunkerweb-scheduler:1.6.11orghcr.io/bunkerity/bunkerweb-scheduler:1.6.11 - Autoconf :
bunkerity/bunkerweb-autoconf:1.6.11orghcr.io/bunkerity/bunkerweb-autoconf:1.6.11 - UI :
bunkerity/bunkerweb-ui:1.6.11orghcr.io/bunkerity/bunkerweb-ui:1.6.11 - API :
bunkerity/bunkerweb-api:1.6.11orghcr.io/bunkerity/bunkerweb-api:1.6.11
Linux packages : https://packagecloud.io/app/bunkerity/bunkerweb/search?q=1.6.11&filter=all&dist=
Changelog :
- [SECURITY]
nginx: update nginx to 1.30.2 (except for Fedora as it is not yet available) to fix CVE-2026-9256 — a heap buffer overflow inngx_http_rewrite_modulewith overlapping captures that could lead to worker-process arbitrary code execution.
Security Fixes
- CVE-2026-9256 — heap buffer overflow in ngx_http_rewrite_module causing worker-process arbitrary code execution
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Related tools
Beta — feedback welcome: [email protected]