nginx-1.29.5 mainline version has been released. This release includes a security fix for the SSL upstream injection vulnerability (CVE-2026-1642). See official CHANGES on nginx.org.
Below is a release summary generated by GitHub.
What's Changed
- Fixed duplicate ids in the bug report template. by @bavshin-f5 in https://github.com/nginx/nginx/pull/1035
- SSL: logging level of the "ech_required" TLS alert. by @arut in https://github.com/nginx/nginx/pull/1038
- Win32: fixed C4319 warning with MSVC x86. by @bavshin-f5 in https://github.com/nginx/nginx/pull/1057
- Add a HTTP_HOST parameter to default_params. by @ac000 in https://github.com/nginx/nginx/pull/1031
- Year 2026. by @pluknet in https://github.com/nginx/nginx/pull/1076
- Range filter: reasonable limit on multiple ranges. by @pluknet in https://github.com/nginx/nginx/pull/1075
- Misc: moved documentation in generated ZIP archive. by @pluknet in https://github.com/nginx/nginx/pull/1078
- Docs: Clarify -t option behavior in nginx man page by @uhliarik in https://github.com/nginx/nginx/pull/1089
- Proxy v2 request body fixes. by @pluknet in https://github.com/nginx/nginx/pull/1058
- Updated OpenSSL and PCRE used for win32 builds. by @arut in https://github.com/nginx/nginx/pull/1111
- Upstream read before write by @arut in https://github.com/nginx/nginx/pull/1112
- nginx-1.29.5-RELEASE by @arut in https://github.com/nginx/nginx/pull/1113
New Contributors
- @uhliarik made their first contribution in https://github.com/nginx/nginx/pull/1089
Full Changelog: https://github.com/nginx/nginx/compare/release-1.29.4...release-1.29.5