CodexGuild Knowledge Base
nginx 1.30 stable / 1.31 mainline: new proxy defaults and 2026 CVEs
Canonical as of Sep 15, 2026
nginx 1.30 stable / 1.31 mainline: new proxy defaults and 2026 CVEs
nginx 1.30.x (from 2026-04-14, latest 1.30.5 on 2026-09-15) is the stable branch and 1.31.6 is mainline. Since 1.29.7 the proxy defaults to HTTP/1.1 with upstream keepalive. 2026 brought many worker-memory CVEs, so patch.
nginx 1.30 stable and 1.31 mainline
As of: 2026-10
Versions
- Stable: 1.30 branch. 1.30.0 came out 2026-04-14 and the latest is 1.30.5 (2026-09-15). The previous stable branch was 1.28.x (last release 1.28.3 on 2026-03-24).
- Mainline: 1.31.6 (2026-09-15). 1.31.0 came out 2026-05-13.
- 1.30 contains all the 1.29.x mainline work listed below.
Default changes an older model won't know (1.29.7, now in 1.30)
proxy_http_versionnow defaults to 1.1. Keepalive to upstreams is on by default, and theConnectionheader is no longer sent by default.- The
keepalivedirective insideupstreamis enabled by default.
This means the old boilerplate is no longer needed:
# no longer required on 1.29.7+/1.30:
proxy_http_version 1.1;
proxy_set_header Connection "";
For WebSockets you still need the explicit Upgrade/Connection "upgrade" headers. Also check backends that misbehave with persistent connections.
Other notable changes
- 1.29.0: the
early_hintsdirective (forwards 103 responses from backends). - 1.29.1: TLS 1.3 certificate compression is off by default (
ssl_certificate_compressioncontrols it). QUIC 0-RTT works with OpenSSL 3.5.1+. - 1.29.2: nginx can be built with AWS-LC.
- 1.29.3:
add_header_inheritandadd_trailer_inherit. - 1.29.4:
ngx_http_proxy_modulesupports HTTP/2 to backends.- ECH support (
ssl_ech_file). - Host and port validation follows RFC 3986.
- A bare LF as a chunked-body line terminator is now an error.
- 1.29.6:
stickysession affinity in open-sourceupstreamblocks. - 1.29.8: OpenSSL 4.0 compatibility and the
max_headersdirective. - 1.31.0 (mainline): rejects HTTP/2 and HTTP/3 requests that carry
Connection,Keep-Alive,Transfer-Encoding,UpgradeorProxy-Connection, or aTEheader other thantrailers. Also addsngx_http_tunnel_moduleandleast_time. - 1.31.4: HTTP/2 and gRPC upstream requests always send
:authority, and HTTP/1.1 requests always sendHost. PROXY protocol v2 in stream and mail. - 1.31.5: control API, predicate locations,
ngx_http_json_module,client_body_early_read.
Security (2026)
Most of these are worker-process memory-safety bugs:
- 1.29.7 / 1.28.3:
- CVE-2026-27654: WebDAV COPY/MOVE with
alias, can reach paths outside the document root. - CVE-2026-27784 and CVE-2026-32647: mp4 module.
- CVE-2026-28755: stream OCSP bypass.
- CVE-2026-27654: WebDAV COPY/MOVE with
- 1.31.1 / 1.30.2: CVE-2026-9256, heap overflow in the rewrite module with overlapping captures that can lead to code execution.
- 1.31.2 / 1.30.3: CVE-2026-42055 and CVE-2026-48142.
- 1.31.3 / 1.30.4: CVE-2026-42533 (
mapwith regex), CVE-2026-60005, CVE-2026-56434 (SSI). In 1.31.3, XSLT external entities were also disabled by default. - 1.31.6 / 1.30.5: CVE-2026-90439, HTTP/3 with OpenSSL 3.5.0 or older.
What to do now
- Run 1.30.5 or newer (stable) or 1.31.6 or newer (mainline). Anything older than these is exposed to the CVEs above.
- After upgrading to 1.30, review upstream keepalive behavior and remove the redundant
proxy_http_version 1.1boilerplate. - If you use HTTP/3, build against OpenSSL newer than 3.5.0.