Skip to content

NPMplus

v2026-07-15-r1 Breaking

This release includes 1 breaking change for platform teams planning a safe upgrade.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →

✓ No known CVEs patched in this version

Topics

nginx nginx-php nginx-proxy nginx-proxy-manager nginx-reverse-proxy npmplus

Affected surfaces

auth crypto_tls

ReleasePort's take

Moderate signal
editorial:auto 11d

Always remove the Strict-Transport-Security header in NPMplus when it is not enabled.

Why it matters: Misconfigured HSTS headers can lock browsers to HTTPS and cause access issues; removal prevents unintended enforcement in NPMplus deployments.

Summary

AI summary

Updates Image tags, UI, and breaking across a mixed release.

Changes in this release

Breaking High

Always remove Strict-Transport-Security header if not enabled in NPMplus

Always remove Strict-Transport-Security header if not enabled in NPMplus

Source: llm_adapter@2026-07-15

Confidence: high

Feature Medium

Add host grouping to all host types via advanced tab in UI

Add host grouping to all host types via advanced tab in UI

Source: llm_adapter@2026-07-15

Confidence: high

Feature Low

Allow final "allow all" access rules in UI

Allow final "allow all" access rules in UI

Source: granite4.1:30b@2026-07-15-audit

Confidence: low

Dependency Medium

Update nginx to version 1.31.3 to fix new CVEs

Update nginx to version 1.31.3 to fix new CVEs

Source: llm_adapter@2026-07-15

Confidence: high

Dependency Low

Perform general dependency updates

Perform general dependency updates

Source: llm_adapter@2026-07-15

Confidence: high

Bugfix Medium

Change default of APPSEC_DROP_UNREADABLE_BODY to false in crowdsec config, fixing broken DELETE requests with empty body

Change default of APPSEC_DROP_UNREADABLE_BODY to false in crowdsec config, fixing broken DELETE requests with empty body

Source: llm_adapter@2026-07-15

Confidence: low

Refactor Low

Update list of hidden headers from OWASP secure-headers project

Update list of hidden headers from OWASP secure-headers project

Source: llm_adapter@2026-07-15

Confidence: high

Full changelog

What Changed since the last release

  • breaking: always remove Strict-Transport-Security header if not enabled in NPMplus
  • nginx: update to 1.31.3 to fix new CVEs
  • UI: add host grouping to all host types (via advanced tab) #3519
  • UI: merge https://github.com/NginxProxyManager/nginx-proxy-manager/pull/5681
  • UI: allow final "allow all" access rules
  • initial startup: change default of APPSEC_DROP_UNREADABLE_BODY in initial crowdsec config file to false since it break DELETE requests with an empty body
  • update list of hidden headers (https://raw.githubusercontent.com/OWASP/www-project-secure-headers/refs/heads/master/ci/headers_remove.json)
  • dep updates

Image tags:

  • docker.io/zoeyvid/npmplus:2026-07-15-r1 (fixed to this release)
  • ghcr.io/zoeyvid/npmplus:2026-07-15-r1 (fixed to this release)
  • docker.io/zoeyvid/npmplus:latest (latest stable)
  • ghcr.io/zoeyvid/npmplus:latest (latest stable)
  • docker.io/zoeyvid/npmplus:beta (latest beta/stable)
  • ghcr.io/zoeyvid/npmplus:beta (latest beta/stable)

Full Changelog: https://github.com/ZoeyVid/NPMplus/compare/2026-06-25-r1...2026-07-15-r1

Breaking Changes

  • Always remove Strict-Transport-Security header if not explicitly enabled in NPMplus configuration.

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track NPMplus

Get notified when new releases ship.

Sign up free

About NPMplus

a fork of nginx-proxy-manager

All releases →

Related context

Beta — feedback welcome: [email protected]