Re: nginx-1.30.2_2,3 wrongly vulnerable to CVE-2026-9256 ?

Fernando ApesteguĂ­a <[email protected]> Fri, 5 Jun 2026 15:35:18 +0200
Newsgroups gmane.os.freebsd.security.general
Message-ID <CAGwOe2brbehmLSiDdsvFrOq4SVwGid3RU1-mVNsQOm7kRCgRpQ@mail.gmail.com>
--00000000000006b5f7065381bc37
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

El vie, 5 jun 2026, 14:47, Arnaud de Prelle <[email protected]> escribi=C3=
=B3:

> Hi all,
>
> Thank you for your adaptations.
>
> Alert has now disappeared from pkg audit -F as the vuXML database now
> shows :
> 0.1.17,3        <=3D      nginx   <       1.30.2_2,3
> 1.31.0,3        <=3D      nginx   <       1.31.1,3
>
> Kind regards,
> Arnaud.
>

Thank you all for reporting and sorry for the mistake.


> On 2026-06-01 22:42, Fernando Apestegu=C3=ADa wrote:
> > Including joneum@ who maintains the port.
> >
> > On Mon, Jun 1, 2026 at 2:26=E2=80=AFPM Martin Simmons <martin@lispworks=
.com>
> > wrote:
> >
> >> [fernape@ added]
> >>
> >> >>>>> On Sun, 31 May 2026 22:01:11 +0200, Arnaud de Prelle said:
> >> >
> >> > Hi,
> >> >
> >> > As per
> >> > - https://www.freshports.org/www/nginx/ and
> >> > -
> >> >
> >>
> https://vuxml.freebsd.org/freebsd/36a3131d-5600-11f1-b339-3497f65b111b.ht=
ml
> >> > CVE-2026-9256 should be fixed since nginx 1.30.2,3.
> >>
> >> The contents of this URL was stale -- the VuXML now says nginx <
> >> 1.31.1,3
> >> (since yesterday), which explains why pkg audit is detecting it.
> >>
> >> > I'm using the latest version of nginx:
> >> > # pkg info nginx | grep Version
> >> > Version        : 1.30.2_2,3
> >> >
> >> > But pkg audit -F reports this port as vulnerable to CVE-2026-9256:
> >> > # pkg audit -F
> >> > vulnxml file up-to-date
> >> > nginx-1.30.2_2,3 is vulnerable:
> >> >    nginx -- heap buffer overflow in ngx_http_rewrite_module
> >> >    CVE: CVE-2026-9256
> >> >    WWW:
> >> >
> >>
> https://vuxml.FreeBSD.org/freebsd/36a3131d-5600-11f1-b339-3497f65b111b.ht=
ml
> >> >
> >> > Am I missing something ?
> >>
> >> The VuXML looks wrong to me now.
> >>
> >> nginx released both 1.30.2 and 1.31.1 to fix this CVE
> >> (https://nginx.org/en/CHANGES-1.30 and https://nginx.org/en/CHANGES).
> >>
> >> __Martin
> >>
>

--00000000000006b5f7065381bc37
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"auto"><div><br><br><div class=3D"gmail_quote gmail_quote_contai=
ner"><div dir=3D"ltr" class=3D"gmail_attr">El vie, 5 jun 2026, 14:47, Arnau=
d de Prelle &lt;<a href=3D"mailto:[email protected]">[email protected]</a>&=
gt; escribi=C3=B3:<br></div><blockquote class=3D"gmail_quote" style=3D"marg=
in:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">Hi all,<br>
<br>
Thank you for your adaptations.<br>
<br>
Alert has now disappeared from pkg audit -F as the vuXML database now <br>
shows :<br>
0.1.17,3=C2=A0 =C2=A0 =C2=A0 =C2=A0 &lt;=3D=C2=A0 =C2=A0 =C2=A0 nginx=C2=A0=
 =C2=A0&lt;=C2=A0 =C2=A0 =C2=A0 =C2=A01.30.2_2,3<br>
1.31.0,3=C2=A0 =C2=A0 =C2=A0 =C2=A0 &lt;=3D=C2=A0 =C2=A0 =C2=A0 nginx=C2=A0=
 =C2=A0&lt;=C2=A0 =C2=A0 =C2=A0 =C2=A01.31.1,3<br>
<br>
Kind regards,<br>
Arnaud.<br></blockquote></div></div><div dir=3D"auto"><br></div><div dir=3D=
"auto">Thank you all for reporting and sorry for the mistake.</div><div dir=
=3D"auto"><br></div><div dir=3D"auto"><div class=3D"gmail_quote gmail_quote=
_container"><blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;bo=
rder-left:1px #ccc solid;padding-left:1ex">
<br>
On 2026-06-01 22:42, Fernando Apestegu=C3=ADa wrote:<br>
&gt; Including joneum@ who maintains the port.<br>
&gt; <br>
&gt; On Mon, Jun 1, 2026 at 2:26=E2=80=AFPM Martin Simmons &lt;<a href=3D"m=
ailto:[email protected]" target=3D"_blank" rel=3D"noreferrer">martin@lis=
pworks.com</a>&gt; <br>
&gt; wrote:<br>
&gt; <br>
&gt;&gt; [fernape@ added]<br>
&gt;&gt; <br>
&gt;&gt; &gt;&gt;&gt;&gt;&gt; On Sun, 31 May 2026 22:01:11 +0200, Arnaud de=
 Prelle said:<br>
&gt;&gt; &gt;<br>
&gt;&gt; &gt; Hi,<br>
&gt;&gt; &gt;<br>
&gt;&gt; &gt; As per<br>
&gt;&gt; &gt; - <a href=3D"https://www.freshports.org/www/nginx/" rel=3D"no=
referrer noreferrer" target=3D"_blank">https://www.freshports.org/www/nginx=
/</a> and<br>
&gt;&gt; &gt; -<br>
&gt;&gt; &gt;<br>
&gt;&gt; <a href=3D"https://vuxml.freebsd.org/freebsd/36a3131d-5600-11f1-b3=
39-3497f65b111b.html" rel=3D"noreferrer noreferrer" target=3D"_blank">https=
://vuxml.freebsd.org/freebsd/36a3131d-5600-11f1-b339-3497f65b111b.html</a><=
br>
&gt;&gt; &gt; CVE-2026-9256 should be fixed since nginx 1.30.2,3.<br>
&gt;&gt; <br>
&gt;&gt; The contents of this URL was stale -- the VuXML now says nginx &lt=
; <br>
&gt;&gt; 1.31.1,3<br>
&gt;&gt; (since yesterday), which explains why pkg audit is detecting it.<b=
r>
&gt;&gt; <br>
&gt;&gt; &gt; I&#39;m using the latest version of nginx:<br>
&gt;&gt; &gt; # pkg info nginx | grep Version<br>
&gt;&gt; &gt; Version=C2=A0 =C2=A0 =C2=A0 =C2=A0 : 1.30.2_2,3<br>
&gt;&gt; &gt;<br>
&gt;&gt; &gt; But pkg audit -F reports this port as vulnerable to CVE-2026-=
9256:<br>
&gt;&gt; &gt; # pkg audit -F<br>
&gt;&gt; &gt; vulnxml file up-to-date<br>
&gt;&gt; &gt; nginx-1.30.2_2,3 is vulnerable:<br>
&gt;&gt; &gt;=C2=A0 =C2=A0 nginx -- heap buffer overflow in ngx_http_rewrit=
e_module<br>
&gt;&gt; &gt;=C2=A0 =C2=A0 CVE: CVE-2026-9256<br>
&gt;&gt; &gt;=C2=A0 =C2=A0 WWW:<br>
&gt;&gt; &gt;<br>
&gt;&gt; <a href=3D"https://vuxml.FreeBSD.org/freebsd/36a3131d-5600-11f1-b3=
39-3497f65b111b.html" rel=3D"noreferrer noreferrer" target=3D"_blank">https=
://vuxml.FreeBSD.org/freebsd/36a3131d-5600-11f1-b339-3497f65b111b.html</a><=
br>
&gt;&gt; &gt;<br>
&gt;&gt; &gt; Am I missing something ?<br>
&gt;&gt; <br>
&gt;&gt; The VuXML looks wrong to me now.<br>
&gt;&gt; <br>
&gt;&gt; nginx released both 1.30.2 and 1.31.1 to fix this CVE<br>
&gt;&gt; (<a href=3D"https://nginx.org/en/CHANGES-1.30" rel=3D"noreferrer n=
oreferrer" target=3D"_blank">https://nginx.org/en/CHANGES-1.30</a> and <a h=
ref=3D"https://nginx.org/en/CHANGES" rel=3D"noreferrer noreferrer" target=
=3D"_blank">https://nginx.org/en/CHANGES</a>).<br>
&gt;&gt; <br>
&gt;&gt; __Martin<br>
&gt;&gt; <br>
</blockquote></div></div></div>

--00000000000006b5f7065381bc37--