openwrt / openwrt/packages

nginx: Vulnerable to CVE-2026-42945

Open
#29,480 2 comments 1 reaction 0 assignees View on GitHub

Nobody has claimed this yet.

bug
Dominant language
Makefile
Stars
4.6k
Forks
4k
Avg merge
3d 12h
Merged PRs (30d)
134

Description

Package Name

nginx

Maintainer

Thomas Heil heil@terminal-consulting.de Christian Marangi ansuelsmth@gmail.com

OpenWrt Version

25.12.4

OpenWrt Target/Subtarget

ramips/mt7621, all

Steps to Reproduce

Install nginx-full via apk

Actual Behaviour

Hi,
at the moment the provided package for nginx has the version 1.26.3-r3. Unfortunately it is vulnerable to CVE-2026-42945 and also no longer receives security patches.
The current version would be 1.31 which is not vulnerable https://nginx.org/en/security_advisories.html .
Is there a chance to get this package updated in the official repositories?

Confirmation Checklist

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Locate the OpenWrt nginx package definition and review how its current 1.26.3-r3 version is declared. Check the nginx security advisory linked in the issue, update the package to a supported non-vulnerable release, then install nginx-full via apk to verify that the repository provides the updated version.

Written by the indexing model from the issue text.

Assessment

Tech stack
nginx
Domain
devops, security
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
52/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.