This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+11 more
Affected surfaces
Summary
AI summaryUpgraded Nginx components mitigate CVE-2026-49975 security risk.
Full changelog
Release Notes
This release focuses on security hardening, an upgrade to the Threat Intelligence Sharing program, and several stability and user experience fixes. Community Edition users are advised to update promptly.
Security Hardening
- Upgraded Nginx-related components to mitigate the potential security risk of CVE-2026-49975 and improve the runtime security of the protection service.
- Fixed an edge case in static file path handling related to Auth,improving security when abnormal paths are accessed.
Improvements
- Upgraded Threat Intelligence Sharing.
- Updated the IP geo location database.
Bug Fixes
- Fixed an issue where the application access log could automatically switch back to the real time log after refresh or polling while viewing the History log.
- Fixed an issue where a failed Free Cert application or renewal could trigger an abnormal full rebuild of application configuration.
- Optimized certificate synchronization and configuration reload logic to reduce unnecessary Nginx/MGT reloads when certificate content has not changed.
Security Fixes
- CVE-2026-49975 — mitigated by upgrading Nginx-related components; fixed static file path handling edge case in Auth
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About SafeLine
SafeLine is a self-hosted WAF(Web Application Firewall) / reverse proxy to protect your web apps from attacks and exploits.
Related context
Related tools
Beta — feedback welcome: [email protected]