nginx: Vulnerable to CVE-2026-42945
Nobody has claimed this yet.
- Dominant language
- Makefile
- Stars
- 4.6k
- Forks
- 4k
- Avg merge
- 3d 12h
- Merged PRs (30d)
- 134
Description
Package Name
nginx
Maintainer
Thomas Heil heil@terminal-consulting.de Christian Marangi ansuelsmth@gmail.com
OpenWrt Version
25.12.4
OpenWrt Target/Subtarget
ramips/mt7621, all
Steps to Reproduce
Install nginx-full via apk
Actual Behaviour
Hi,
at the moment the provided package for nginx has the version 1.26.3-r3. Unfortunately it is vulnerable to CVE-2026-42945 and also no longer receives security patches.
The current version would be 1.31 which is not vulnerable https://nginx.org/en/security_advisories.html .
Is there a chance to get this package updated in the official repositories?
Confirmation Checklist
- The package is maintained in this repository.
- I understand that issues related to the base OpenWrt repository or LuCI repository will be closed.
- I am reporting an issue for OpenWrt, not an unsupported fork.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Locate the OpenWrt nginx package definition and review how its current 1.26.3-r3 version is declared. Check the nginx security advisory linked in the issue, update the package to a supported non-vulnerable release, then install nginx-full via apk to verify that the repository provides the updated version.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- nginx
- Domain
- devops, security
- Issue type
- Bug
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Quiet
- Clarity
- Mostly clear
- Newbie friendliness
- 52/100