Re: nginx-1.30.2_2,3 wrongly vulnerable to CVE-2026-9256 ?

Fernando ApesteguĂ­a <[email protected]> Mon, 1 Jun 2026 22:42:16 +0200
Newsgroups gmane.os.freebsd.security.general
Message-ID <CAGwOe2ZdZ=M4dunqTtSk6J=9cwJKuCzg8u9C9hOg2t2Sf80opQ@mail.gmail.com>
--0000000000009ff0520653373b3c
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

Including joneum@ who maintains the port.

On Mon, Jun 1, 2026 at 2:26=E2=80=AFPM Martin Simmons <[email protected]=
> wrote:

> [fernape@ added]
>
> >>>>> On Sun, 31 May 2026 22:01:11 +0200, Arnaud de Prelle said:
> >
> > Hi,
> >
> > As per
> > - https://www.freshports.org/www/nginx/ and
> > -
> >
> https://vuxml.freebsd.org/freebsd/36a3131d-5600-11f1-b339-3497f65b111b.ht=
ml
> > CVE-2026-9256 should be fixed since nginx 1.30.2,3.
>
> The contents of this URL was stale -- the VuXML now says nginx < 1.31.1,3
> (since yesterday), which explains why pkg audit is detecting it.
>
> > I'm using the latest version of nginx:
> > # pkg info nginx | grep Version
> > Version        : 1.30.2_2,3
> >
> > But pkg audit -F reports this port as vulnerable to CVE-2026-9256:
> > # pkg audit -F
> > vulnxml file up-to-date
> > nginx-1.30.2_2,3 is vulnerable:
> >    nginx -- heap buffer overflow in ngx_http_rewrite_module
> >    CVE: CVE-2026-9256
> >    WWW:
> >
> https://vuxml.FreeBSD.org/freebsd/36a3131d-5600-11f1-b339-3497f65b111b.ht=
ml
> >
> > Am I missing something ?
>
> The VuXML looks wrong to me now.
>
> nginx released both 1.30.2 and 1.31.1 to fix this CVE
> (https://nginx.org/en/CHANGES-1.30 and https://nginx.org/en/CHANGES).
>
> __Martin
>

--0000000000009ff0520653373b3c
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div>Including joneum@ who maintains the port.</div><br><d=
iv class=3D"gmail_quote gmail_quote_container"><div dir=3D"ltr" class=3D"gm=
ail_attr">On Mon, Jun 1, 2026 at 2:26=E2=80=AFPM Martin Simmons &lt;<a href=
=3D"mailto:[email protected]">[email protected]</a>&gt; wrote:<br></d=
iv><blockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;bord=
er-left:1px solid rgb(204,204,204);padding-left:1ex">[fernape@ added]<br>
<br>
&gt;&gt;&gt;&gt;&gt; On Sun, 31 May 2026 22:01:11 +0200, Arnaud de Prelle s=
aid:<br>
&gt; <br>
&gt; Hi,<br>
&gt; <br>
&gt; As per<br>
&gt; - <a href=3D"https://www.freshports.org/www/nginx/" rel=3D"noreferrer"=
 target=3D"_blank">https://www.freshports.org/www/nginx/</a> and<br>
&gt; - <br>
&gt; <a href=3D"https://vuxml.freebsd.org/freebsd/36a3131d-5600-11f1-b339-3=
497f65b111b.html" rel=3D"noreferrer" target=3D"_blank">https://vuxml.freebs=
d.org/freebsd/36a3131d-5600-11f1-b339-3497f65b111b.html</a><br>
&gt; CVE-2026-9256 should be fixed since nginx 1.30.2,3.<br>
<br>
The contents of this URL was stale -- the VuXML now says nginx &lt; 1.31.1,=
3<br>
(since yesterday), which explains why pkg audit is detecting it.<br>
<br>
&gt; I&#39;m using the latest version of nginx:<br>
&gt; # pkg info nginx | grep Version<br>
&gt; Version=C2=A0 =C2=A0 =C2=A0 =C2=A0 : 1.30.2_2,3<br>
&gt; <br>
&gt; But pkg audit -F reports this port as vulnerable to CVE-2026-9256:<br>
&gt; # pkg audit -F<br>
&gt; vulnxml file up-to-date<br>
&gt; nginx-1.30.2_2,3 is vulnerable:<br>
&gt;=C2=A0 =C2=A0 nginx -- heap buffer overflow in ngx_http_rewrite_module<=
br>
&gt;=C2=A0 =C2=A0 CVE: CVE-2026-9256<br>
&gt;=C2=A0 =C2=A0 WWW: <br>
&gt; <a href=3D"https://vuxml.FreeBSD.org/freebsd/36a3131d-5600-11f1-b339-3=
497f65b111b.html" rel=3D"noreferrer" target=3D"_blank">https://vuxml.FreeBS=
D.org/freebsd/36a3131d-5600-11f1-b339-3497f65b111b.html</a><br>
&gt; <br>
&gt; Am I missing something ?<br>
<br>
The VuXML looks wrong to me now.<br>
<br>
nginx released both 1.30.2 and 1.31.1 to fix this CVE<br>
(<a href=3D"https://nginx.org/en/CHANGES-1.30" rel=3D"noreferrer" target=3D=
"_blank">https://nginx.org/en/CHANGES-1.30</a> and <a href=3D"https://nginx=
.org/en/CHANGES" rel=3D"noreferrer" target=3D"_blank">https://nginx.org/en/=
CHANGES</a>).<br>
<br>
__Martin<br>
</blockquote></div></div>

--0000000000009ff0520653373b3c--