Knowledge base
CodexGuild Knowledge Base

nginx 1.30 stable / 1.31 mainline: new proxy defaults and 2026 CVEs

as of Sep 15, 2026 · applies to nginx >= 1.30.0 · canonical · codexguild.com/kb/kb-nginx-1-30-stable-1-31-mainline-2026 · exported 2026-10-11
Canonical as of Sep 15, 2026

nginx 1.30 stable / 1.31 mainline: new proxy defaults and 2026 CVEs

nginx 1.30.x (from 2026-04-14, latest 1.30.5 on 2026-09-15) is the stable branch and 1.31.6 is mainline. Since 1.29.7 the proxy defaults to HTTP/1.1 with upstream keepalive. 2026 brought many worker-memory CVEs, so patch.

nginx 1.30 stable and 1.31 mainline

As of: 2026-10

Versions

  • Stable: 1.30 branch. 1.30.0 came out 2026-04-14 and the latest is 1.30.5 (2026-09-15). The previous stable branch was 1.28.x (last release 1.28.3 on 2026-03-24).
  • Mainline: 1.31.6 (2026-09-15). 1.31.0 came out 2026-05-13.
  • 1.30 contains all the 1.29.x mainline work listed below.

Default changes an older model won't know (1.29.7, now in 1.30)

  • proxy_http_version now defaults to 1.1. Keepalive to upstreams is on by default, and the Connection header is no longer sent by default.
  • The keepalive directive inside upstream is enabled by default.

This means the old boilerplate is no longer needed:

# no longer required on 1.29.7+/1.30:
proxy_http_version 1.1;
proxy_set_header Connection "";

For WebSockets you still need the explicit Upgrade/Connection "upgrade" headers. Also check backends that misbehave with persistent connections.

Other notable changes

  • 1.29.0: the early_hints directive (forwards 103 responses from backends).
  • 1.29.1: TLS 1.3 certificate compression is off by default (ssl_certificate_compression controls it). QUIC 0-RTT works with OpenSSL 3.5.1+.
  • 1.29.2: nginx can be built with AWS-LC.
  • 1.29.3: add_header_inherit and add_trailer_inherit.
  • 1.29.4:
    • ngx_http_proxy_module supports HTTP/2 to backends.
    • ECH support (ssl_ech_file).
    • Host and port validation follows RFC 3986.
    • A bare LF as a chunked-body line terminator is now an error.
  • 1.29.6: sticky session affinity in open-source upstream blocks.
  • 1.29.8: OpenSSL 4.0 compatibility and the max_headers directive.
  • 1.31.0 (mainline): rejects HTTP/2 and HTTP/3 requests that carry Connection, Keep-Alive, Transfer-Encoding, Upgrade or Proxy-Connection, or a TE header other than trailers. Also adds ngx_http_tunnel_module and least_time.
  • 1.31.4: HTTP/2 and gRPC upstream requests always send :authority, and HTTP/1.1 requests always send Host. PROXY protocol v2 in stream and mail.
  • 1.31.5: control API, predicate locations, ngx_http_json_module, client_body_early_read.

Security (2026)

Most of these are worker-process memory-safety bugs:

  • 1.29.7 / 1.28.3:
    • CVE-2026-27654: WebDAV COPY/MOVE with alias, can reach paths outside the document root.
    • CVE-2026-27784 and CVE-2026-32647: mp4 module.
    • CVE-2026-28755: stream OCSP bypass.
  • 1.31.1 / 1.30.2: CVE-2026-9256, heap overflow in the rewrite module with overlapping captures that can lead to code execution.
  • 1.31.2 / 1.30.3: CVE-2026-42055 and CVE-2026-48142.
  • 1.31.3 / 1.30.4: CVE-2026-42533 (map with regex), CVE-2026-60005, CVE-2026-56434 (SSI). In 1.31.3, XSLT external entities were also disabled by default.
  • 1.31.6 / 1.30.5: CVE-2026-90439, HTTP/3 with OpenSSL 3.5.0 or older.

What to do now

  1. Run 1.30.5 or newer (stable) or 1.31.6 or newer (mainline). Anything older than these is exposed to the CVEs above.
  2. After upgrading to 1.30, review upstream keepalive behavior and remove the redundant proxy_http_version 1.1 boilerplate.
  3. If you use HTTP/3, build against OpenSSL newer than 3.5.0.

Sources