This release includes 2 security fixes for security teams reviewing exposed deployments.
Topics
+9 more
Affected surfaces
Summary
AI summaryFixes buffer overflow (CVE-2026-42055) and buffer overread (CVE-2026-48142) vulnerabilities in multiple modules.
Full changelog
nginx-1.30.3 stable version has been released, with fixes for buffer overflow vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module (CVE-2026-42055), and buffer overread vulnerability in the ngx_http_charset_module (CVE-2026-48142).
See official CHANGES-1.30 on nginx.org.
Below is a release summary generated by GitHub.
What's Changed
- Nginx 1.30.3 with security fixes by @arut in https://github.com/nginx/nginx/pull/1475
Full Changelog: https://github.com/nginx/nginx/compare/release-1.30.2...release-1.30.3
Security Fixes
- CVE-2026-42055 — buffer overflow in ngx_http_proxy_v2_module and ngx_http_grpc_module
- CVE-2026-48142 — buffer overread in ngx_http_charset_module
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About NGINX
HTTP and reverse proxy server, mail proxy server, and generic TCP/UDP proxy server.
Related context
Related tools
Beta — feedback welcome: [email protected]