Releases: HomeLabHD/nginx-extras
Release list
latest-dev
📦 nginx-extras — v0.0.6-dev+b5eaa1b
Release type: prerelease • Commit:
b5eaa1b
Security: 🛡️ ❌ Critical — 6 critical and 9 high vulnerabilities detected
Image Availability
| Registry | Image | Tags |
|---|---|---|
| Docker Hub | docker.io/hlhd/nginx-extras |
dev-b5eaa1b latest-dev |
| cr.pcfae.com | cr.pcfae.com/hlhd/nginx-extras |
dev-b5eaa1b latest-dev |
| GitHub Container Registry | ghcr.io/homelabhd/nginx-extras |
dev-b5eaa1b latest-dev |
Digest pull commands & supply chain artifacts
docker.io/hlhd/nginx-extras
docker pull docker.io/hlhd/nginx-extras@sha256:5e38efe5add1602927161ba6ca3d59eba15033b7de7b8f73ff23b03e774790d2
cr.pcfae.com/hlhd/nginx-extras
docker pull cr.pcfae.com/hlhd/nginx-extras@sha256:5e38efe5add1602927161ba6ca3d59eba15033b7de7b8f73ff23b03e774790d2
ghcr.io/homelabhd/nginx-extras
docker pull ghcr.io/homelabhd/nginx-extras@sha256:5e38efe5add1602927161ba6ca3d59eba15033b7de7b8f73ff23b03e774790d2
Notable Changes
Documentation
- refresh generated badges (stagefreight) ×15
Maintenance
- governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) ×14
- governance reconcile from PrPlanIT/MaintenancePolicy 11066049d06cb0e071409a80bc96411b0a899d1e (StageFreight)
- governance reconcile from PrPlanIT/MaintenancePolicy 44ce7931b90a3386783ed4f03a822f98eb8128de (StageFreight)
- governance reconcile from PrPlanIT/MaintenancePolicy 2fcb480f6f7c686b6e35251e415249617752757b (StageFreight)
- governance reconcile from PrPlanIT/MaintenancePolicy be6129b7d6583ac9fc8b2483c0e23fd1c67a5069 (StageFreight)
- deps: update managed dependencies (stagefreight)
- re-render .gitlab-ci.yml for the governed config (SoFMeRight)
- governance reconcile from PrPlanIT/MaintenancePolicy 643a4fdc2e87ac974407c3864a42f957fa9c56e5 (StageFreight)
- rename Readme.md to README.md; add GPL-3.0 LICENSE; retarget image to hlhd/nginx-extras (SoFMeRight)
- governance reconcile from PrPlanIT/MaintenancePolicy 814d185bc7dd335963b721170a179791bce141fc (StageFreight)
Security
🛡️ ❌ Critical — 6 critical and 9 high vulnerabilities detected
Vulnerability details (6 critical, 9 high, 18 medium, 1 low)
| Severity | CVE | Package | Installed | Fixed | Description |
|---|---|---|---|---|---|
| Critical | CVE-2026-9079 | curl | 8.14.1-r3 | — | libcurl had a flaw that when instructed to clear proxy au... |
| Critical | CVE-2026-10536 | curl | 8.14.1-r3 | — | A use-after-free vulnerability exists in libcurl when an ... |
| Critical | CVE-2026-11856 | curl | 8.14.1-r3 | — | Successfully using libcurl to do a transfer to a specific... |
| Critical | CVE-2026-8924 | curl | 8.14.1-r3 | — | A flaw in curl’s cookie parsing logic allows a maliciou... |
| Critical | CVE-2026-8927 | curl | 8.14.1-r3 | — | When reusing a libcurl handle for sequential transfers dr... |
| Critical | CVE-2026-8926 | curl | 8.14.1-r3 | — | When asking curl to use a .netrc file to find credentia... |
| High | CVE-2026-3805 | curl | 8.14.1-r3 | — | When doing a second SMB request to the same host again, c... |
| High | CVE-2026-5773 | curl | 8.14.1-r3 | — | libcurl might in some circumstances reuse the wrong conne... |
| High | CVE-2026-12064 | curl | 8.14.1-r3 | — | When a user invokes curl using a schemeless URL combined ... |
| High | CVE-2026-8932 | curl | 8.14.1-r3 | — | libcurl would reuse a previously created connection even ... |
| High | CVE-2026-9547 | curl | 8.14.1-r3 | — | When a libcurl-based application performs transfers via `... |
| High | CVE-2026-8286 | curl | 8.14.1-r3 | — | A vulnerability exists where a new transfer that uses STA... |
| High | CVE-2026-6276 | curl | 8.14.1-r3 | — | Using libcurl, when a custom Host: header is first set ... |
| High | CVE-2026-9080 | curl | 8.14.1-r3 | — | Calling curl_easy_pause() within the event-based `CURLM... |
| High | CVE-2026-9545 | curl | 8.14.1-r3 | — | In this scenario, libcurl first uses a proper HTTP/3 serv... |
| Medium | CVE-2026-6253 | curl | 8.14.1-r3 | — | curl might erroneously pass on credentials for a first pr... |
| Medium | CVE-2025-14819 | curl | 8.14.1-r3 | — | When doing TLS related transfers with reused easy or mult... |
| Medium | CVE-2025-14524 | curl | 8.14.1-r3 | — | When an OAuth2 bearer token is used for an HTTP(S) transf... |
| Medium | CVE-2026-8458 | curl | 8.14.1-r3 | — | libcurl might in some circumstances reuse the wrong conne... |
| Medium | CVE-2026-6429 | curl | 8.14.1-r3 | — | When asked to both use a .netrc file for credentials an... |
| Medium | CVE-2025-15079 | curl | 8.14.1-r3 | — | When doing SSH-based transfers using either SCP or SFTP, ... |
| Medium | CVE-2026-7168 | curl | 8.14.1-r3 | — | Successfully using libcurl to do a transfer over a specif... |
| Medium | CVE-2026-3784 | curl | 8.14.1-r3 | — | curl would wrongly reuse an existing HTTP proxy connectio... |
| Medium | CVE-2026-3783 | curl | 8.14.1-r3 | — | When an OAuth2 bearer token is used for an HTTP(S) transf... |
| Medium | CVE-2025-10966 | curl | 8.14.1-r3 | — | curl's code for managing SSH connections when SFTP was do... |
| Medium | CVE-2026-4873 | curl | 8.14.1-r3 | — | A vulnerability exists where a connection requiring TLS i... |
| Medium | CVE-2025-60876 | busybox | 1.37.0-r20 | — | BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) ... |
| Medium | CVE-2025-60876 | busybox-binsh | 1.37.0-r20 | — | BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) ... |
| Medium | CVE-2025-60876 | ssl_client | 1.37.0-r20 | — | BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) ... |
| Medium | CVE-2026-1965 | curl | 8.14.1-r3 | — | libcurl can in some circumstances reuse the wrong connect... |
| Medium | CVE-2026-58055 | nghttp2-libs | 1.69.0-r0 | — | nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1... |
| Medium | CVE-2025-13034 | curl | 8.14.1-r3 | — | When using CURLOPT_PINNEDPUBLICKEY option with libcurl ... |
| Medium | CVE-2025-14017 | curl | 8.14.1-r3 | — | When doing multi-threaded LDAPS transfers (LDAP over TLS)... |
| Low | CVE-2025-15224 | curl | 8.14.1-r3 | — | When doing SSH-based transfers using either SCP or SFTP, ... |
Full changelog
- [
b5eaa1b] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) - [
fb67f2e] refresh generated badges (stagefreight) - [
e15fef2] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) - [
ec749f0] refresh generated badges (stagefreight) - [
98f9dda] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) - [
173fe4f] refresh generated badges (stagefreight) - [
295476e] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) - [
afdcb8f] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) - [
3ece56e] refresh generated badges (stagefreight) - [
e16ab4e] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) - [
9764a74] refresh generated badges (stagefreight) - [
2332fba] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) - [
e404a97] refresh generated badges (stagefreight) - [
5259eba] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) - [
5fb0cae] refresh generated badges (stagefreight) - [
6b71d86] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) - [
a1a4edc] refresh generated badges (stagefreight) - [
331cc8a] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) - [
c3adb29] refresh generated badges (stagefreight) - [
41cb426] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) - [
8815c9e] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) - [
7dde143] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) - [
83e2395] refresh generated badges (stagefreight) - [
cbd1e41] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) - [
6860706] refresh generated badges (stagefreight) - [
4809079] governance reconcile from PrPlanIT/MaintenancePolicy 11066049d06cb0e071409a80bc96411b0a899d1e (StageFreight) - [
bbecd92] refresh generated badges (stagefreight) - [
b076551] governance reconcile from PrPlanIT/MaintenancePolicy 44ce7931b90a3386783ed4f03a822f98eb8128de (StageFreight) - [
291efd2] refresh generated badges (stagefreight) - [
85e71a2] governance reconcile from PrPlanIT/MaintenancePolicy 2fcb480f6f7c686b6e35251e415249617752757b (StageFreight) - [
ce5916a] refresh generated badges (stagefreight) - [
fbef8ab] governance reconcile from PrPlanIT/MaintenancePolicy be6129b7d6583ac9fc8b2483c0e23fd1c67a5069 (StageFreight) - [
8ebc2fc] refresh generated badges (stagefreight) - [
238d7fa] update managed dependencies (stagefreight) - [
ebdb30e] re-render .gitlab-ci.yml for the governed config (SoFMeRight) - [
f68521d] governance reconcile from PrPlanIT/MaintenancePolicy 643a4fdc2e87ac974407c3864a42f957fa9c56e5 (StageFreight) - [
bf18a4b] rename Readme.md to README.md; add GPL-3.0 LICENSE; retarge...
dev-b5eaa1b
📦 nginx-extras — v0.0.6-dev+b5eaa1b
Release type: prerelease • Commit:
b5eaa1b
Security: 🛡️ ❌ Critical — 6 critical and 9 high vulnerabilities detected
Image Availability
| Registry | Image | Tags |
|---|---|---|
| Docker Hub | docker.io/hlhd/nginx-extras |
dev-b5eaa1b latest-dev |
| cr.pcfae.com | cr.pcfae.com/hlhd/nginx-extras |
dev-b5eaa1b latest-dev |
| GitHub Container Registry | ghcr.io/homelabhd/nginx-extras |
dev-b5eaa1b latest-dev |
Digest pull commands & supply chain artifacts
docker.io/hlhd/nginx-extras
docker pull docker.io/hlhd/nginx-extras@sha256:5e38efe5add1602927161ba6ca3d59eba15033b7de7b8f73ff23b03e774790d2
cr.pcfae.com/hlhd/nginx-extras
docker pull cr.pcfae.com/hlhd/nginx-extras@sha256:5e38efe5add1602927161ba6ca3d59eba15033b7de7b8f73ff23b03e774790d2
ghcr.io/homelabhd/nginx-extras
docker pull ghcr.io/homelabhd/nginx-extras@sha256:5e38efe5add1602927161ba6ca3d59eba15033b7de7b8f73ff23b03e774790d2
Notable Changes
Documentation
- refresh generated badges (stagefreight) ×15
Maintenance
- governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) ×14
- governance reconcile from PrPlanIT/MaintenancePolicy 11066049d06cb0e071409a80bc96411b0a899d1e (StageFreight)
- governance reconcile from PrPlanIT/MaintenancePolicy 44ce7931b90a3386783ed4f03a822f98eb8128de (StageFreight)
- governance reconcile from PrPlanIT/MaintenancePolicy 2fcb480f6f7c686b6e35251e415249617752757b (StageFreight)
- governance reconcile from PrPlanIT/MaintenancePolicy be6129b7d6583ac9fc8b2483c0e23fd1c67a5069 (StageFreight)
- deps: update managed dependencies (stagefreight)
- re-render .gitlab-ci.yml for the governed config (SoFMeRight)
- governance reconcile from PrPlanIT/MaintenancePolicy 643a4fdc2e87ac974407c3864a42f957fa9c56e5 (StageFreight)
- rename Readme.md to README.md; add GPL-3.0 LICENSE; retarget image to hlhd/nginx-extras (SoFMeRight)
- governance reconcile from PrPlanIT/MaintenancePolicy 814d185bc7dd335963b721170a179791bce141fc (StageFreight)
Security
🛡️ ❌ Critical — 6 critical and 9 high vulnerabilities detected
Vulnerability details (6 critical, 9 high, 18 medium, 1 low)
| Severity | CVE | Package | Installed | Fixed | Description |
|---|---|---|---|---|---|
| Critical | CVE-2026-9079 | curl | 8.14.1-r3 | — | libcurl had a flaw that when instructed to clear proxy au... |
| Critical | CVE-2026-10536 | curl | 8.14.1-r3 | — | A use-after-free vulnerability exists in libcurl when an ... |
| Critical | CVE-2026-11856 | curl | 8.14.1-r3 | — | Successfully using libcurl to do a transfer to a specific... |
| Critical | CVE-2026-8924 | curl | 8.14.1-r3 | — | A flaw in curl’s cookie parsing logic allows a maliciou... |
| Critical | CVE-2026-8927 | curl | 8.14.1-r3 | — | When reusing a libcurl handle for sequential transfers dr... |
| Critical | CVE-2026-8926 | curl | 8.14.1-r3 | — | When asking curl to use a .netrc file to find credentia... |
| High | CVE-2026-3805 | curl | 8.14.1-r3 | — | When doing a second SMB request to the same host again, c... |
| High | CVE-2026-5773 | curl | 8.14.1-r3 | — | libcurl might in some circumstances reuse the wrong conne... |
| High | CVE-2026-12064 | curl | 8.14.1-r3 | — | When a user invokes curl using a schemeless URL combined ... |
| High | CVE-2026-8932 | curl | 8.14.1-r3 | — | libcurl would reuse a previously created connection even ... |
| High | CVE-2026-9547 | curl | 8.14.1-r3 | — | When a libcurl-based application performs transfers via `... |
| High | CVE-2026-8286 | curl | 8.14.1-r3 | — | A vulnerability exists where a new transfer that uses STA... |
| High | CVE-2026-6276 | curl | 8.14.1-r3 | — | Using libcurl, when a custom Host: header is first set ... |
| High | CVE-2026-9080 | curl | 8.14.1-r3 | — | Calling curl_easy_pause() within the event-based `CURLM... |
| High | CVE-2026-9545 | curl | 8.14.1-r3 | — | In this scenario, libcurl first uses a proper HTTP/3 serv... |
| Medium | CVE-2026-6253 | curl | 8.14.1-r3 | — | curl might erroneously pass on credentials for a first pr... |
| Medium | CVE-2025-14819 | curl | 8.14.1-r3 | — | When doing TLS related transfers with reused easy or mult... |
| Medium | CVE-2025-14524 | curl | 8.14.1-r3 | — | When an OAuth2 bearer token is used for an HTTP(S) transf... |
| Medium | CVE-2026-8458 | curl | 8.14.1-r3 | — | libcurl might in some circumstances reuse the wrong conne... |
| Medium | CVE-2026-6429 | curl | 8.14.1-r3 | — | When asked to both use a .netrc file for credentials an... |
| Medium | CVE-2025-15079 | curl | 8.14.1-r3 | — | When doing SSH-based transfers using either SCP or SFTP, ... |
| Medium | CVE-2026-7168 | curl | 8.14.1-r3 | — | Successfully using libcurl to do a transfer over a specif... |
| Medium | CVE-2026-3784 | curl | 8.14.1-r3 | — | curl would wrongly reuse an existing HTTP proxy connectio... |
| Medium | CVE-2026-3783 | curl | 8.14.1-r3 | — | When an OAuth2 bearer token is used for an HTTP(S) transf... |
| Medium | CVE-2025-10966 | curl | 8.14.1-r3 | — | curl's code for managing SSH connections when SFTP was do... |
| Medium | CVE-2026-4873 | curl | 8.14.1-r3 | — | A vulnerability exists where a connection requiring TLS i... |
| Medium | CVE-2025-60876 | busybox | 1.37.0-r20 | — | BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) ... |
| Medium | CVE-2025-60876 | busybox-binsh | 1.37.0-r20 | — | BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) ... |
| Medium | CVE-2025-60876 | ssl_client | 1.37.0-r20 | — | BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) ... |
| Medium | CVE-2026-1965 | curl | 8.14.1-r3 | — | libcurl can in some circumstances reuse the wrong connect... |
| Medium | CVE-2026-58055 | nghttp2-libs | 1.69.0-r0 | — | nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1... |
| Medium | CVE-2025-13034 | curl | 8.14.1-r3 | — | When using CURLOPT_PINNEDPUBLICKEY option with libcurl ... |
| Medium | CVE-2025-14017 | curl | 8.14.1-r3 | — | When doing multi-threaded LDAPS transfers (LDAP over TLS)... |
| Low | CVE-2025-15224 | curl | 8.14.1-r3 | — | When doing SSH-based transfers using either SCP or SFTP, ... |
Full changelog
- [
b5eaa1b] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) - [
fb67f2e] refresh generated badges (stagefreight) - [
e15fef2] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) - [
ec749f0] refresh generated badges (stagefreight) - [
98f9dda] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) - [
173fe4f] refresh generated badges (stagefreight) - [
295476e] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) - [
afdcb8f] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) - [
3ece56e] refresh generated badges (stagefreight) - [
e16ab4e] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) - [
9764a74] refresh generated badges (stagefreight) - [
2332fba] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) - [
e404a97] refresh generated badges (stagefreight) - [
5259eba] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) - [
5fb0cae] refresh generated badges (stagefreight) - [
6b71d86] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) - [
a1a4edc] refresh generated badges (stagefreight) - [
331cc8a] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) - [
c3adb29] refresh generated badges (stagefreight) - [
41cb426] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) - [
8815c9e] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) - [
7dde143] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) - [
83e2395] refresh generated badges (stagefreight) - [
cbd1e41] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) - [
6860706] refresh generated badges (stagefreight) - [
4809079] governance reconcile from PrPlanIT/MaintenancePolicy 11066049d06cb0e071409a80bc96411b0a899d1e (StageFreight) - [
bbecd92] refresh generated badges (stagefreight) - [
b076551] governance reconcile from PrPlanIT/MaintenancePolicy 44ce7931b90a3386783ed4f03a822f98eb8128de (StageFreight) - [
291efd2] refresh generated badges (stagefreight) - [
85e71a2] governance reconcile from PrPlanIT/MaintenancePolicy 2fcb480f6f7c686b6e35251e415249617752757b (StageFreight) - [
ce5916a] refresh generated badges (stagefreight) - [
fbef8ab] governance reconcile from PrPlanIT/MaintenancePolicy be6129b7d6583ac9fc8b2483c0e23fd1c67a5069 (StageFreight) - [
8ebc2fc] refresh generated badges (stagefreight) - [
238d7fa] update managed dependencies (stagefreight) - [
ebdb30e] re-render .gitlab-ci.yml for the governed config (SoFMeRight) - [
f68521d] governance reconcile from PrPlanIT/MaintenancePolicy 643a4fdc2e87ac974407c3864a42f957fa9c56e5 (StageFreight) - [
bf18a4b] rename Readme.md to README.md; add GPL-3.0 LICENSE; retarge...
dev-e15fef2
📦 nginx-extras — v0.0.6-dev+e15fef2
Release type: prerelease • Commit:
e15fef2
Security: 🛡️ ❌ Critical — 6 critical and 9 high vulnerabilities detected
Image Availability
| Registry | Image | Tags |
|---|---|---|
| Docker Hub | docker.io/hlhd/nginx-extras |
dev-e15fef2 latest-dev |
| cr.pcfae.com | cr.pcfae.com/hlhd/nginx-extras |
dev-e15fef2 latest-dev |
| GitHub Container Registry | ghcr.io/homelabhd/nginx-extras |
dev-e15fef2 latest-dev |
Digest pull commands & supply chain artifacts
docker.io/hlhd/nginx-extras
docker pull docker.io/hlhd/nginx-extras@sha256:8bd9e934ec5ed79062c5f821a9ea52f1228d753c4193436cd01a0e3cdb36a2da
cr.pcfae.com/hlhd/nginx-extras
docker pull cr.pcfae.com/hlhd/nginx-extras@sha256:8bd9e934ec5ed79062c5f821a9ea52f1228d753c4193436cd01a0e3cdb36a2da
ghcr.io/homelabhd/nginx-extras
docker pull ghcr.io/homelabhd/nginx-extras@sha256:8bd9e934ec5ed79062c5f821a9ea52f1228d753c4193436cd01a0e3cdb36a2da
Notable Changes
Documentation
- refresh generated badges (stagefreight) ×14
Maintenance
- governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) ×13
- governance reconcile from PrPlanIT/MaintenancePolicy 11066049d06cb0e071409a80bc96411b0a899d1e (StageFreight)
- governance reconcile from PrPlanIT/MaintenancePolicy 44ce7931b90a3386783ed4f03a822f98eb8128de (StageFreight)
- governance reconcile from PrPlanIT/MaintenancePolicy 2fcb480f6f7c686b6e35251e415249617752757b (StageFreight)
- governance reconcile from PrPlanIT/MaintenancePolicy be6129b7d6583ac9fc8b2483c0e23fd1c67a5069 (StageFreight)
- deps: update managed dependencies (stagefreight)
- re-render .gitlab-ci.yml for the governed config (SoFMeRight)
- governance reconcile from PrPlanIT/MaintenancePolicy 643a4fdc2e87ac974407c3864a42f957fa9c56e5 (StageFreight)
- rename Readme.md to README.md; add GPL-3.0 LICENSE; retarget image to hlhd/nginx-extras (SoFMeRight)
- governance reconcile from PrPlanIT/MaintenancePolicy 814d185bc7dd335963b721170a179791bce141fc (StageFreight)
Security
🛡️ ❌ Critical — 6 critical and 9 high vulnerabilities detected
Vulnerability details (6 critical, 9 high, 18 medium, 1 low)
| Severity | CVE | Package | Installed | Fixed | Description |
|---|---|---|---|---|---|
| Critical | CVE-2026-9079 | curl | 8.14.1-r3 | — | libcurl had a flaw that when instructed to clear proxy au... |
| Critical | CVE-2026-10536 | curl | 8.14.1-r3 | — | A use-after-free vulnerability exists in libcurl when an ... |
| Critical | CVE-2026-11856 | curl | 8.14.1-r3 | — | Successfully using libcurl to do a transfer to a specific... |
| Critical | CVE-2026-8924 | curl | 8.14.1-r3 | — | A flaw in curl’s cookie parsing logic allows a maliciou... |
| Critical | CVE-2026-8927 | curl | 8.14.1-r3 | — | When reusing a libcurl handle for sequential transfers dr... |
| Critical | CVE-2026-8926 | curl | 8.14.1-r3 | — | When asking curl to use a .netrc file to find credentia... |
| High | CVE-2026-3805 | curl | 8.14.1-r3 | — | When doing a second SMB request to the same host again, c... |
| High | CVE-2026-5773 | curl | 8.14.1-r3 | — | libcurl might in some circumstances reuse the wrong conne... |
| High | CVE-2026-12064 | curl | 8.14.1-r3 | — | When a user invokes curl using a schemeless URL combined ... |
| High | CVE-2026-8932 | curl | 8.14.1-r3 | — | libcurl would reuse a previously created connection even ... |
| High | CVE-2026-9547 | curl | 8.14.1-r3 | — | When a libcurl-based application performs transfers via `... |
| High | CVE-2026-8286 | curl | 8.14.1-r3 | — | A vulnerability exists where a new transfer that uses STA... |
| High | CVE-2026-6276 | curl | 8.14.1-r3 | — | Using libcurl, when a custom Host: header is first set ... |
| High | CVE-2026-9080 | curl | 8.14.1-r3 | — | Calling curl_easy_pause() within the event-based `CURLM... |
| High | CVE-2026-9545 | curl | 8.14.1-r3 | — | In this scenario, libcurl first uses a proper HTTP/3 serv... |
| Medium | CVE-2026-6253 | curl | 8.14.1-r3 | — | curl might erroneously pass on credentials for a first pr... |
| Medium | CVE-2025-14819 | curl | 8.14.1-r3 | — | When doing TLS related transfers with reused easy or mult... |
| Medium | CVE-2025-14524 | curl | 8.14.1-r3 | — | When an OAuth2 bearer token is used for an HTTP(S) transf... |
| Medium | CVE-2026-8458 | curl | 8.14.1-r3 | — | libcurl might in some circumstances reuse the wrong conne... |
| Medium | CVE-2026-6429 | curl | 8.14.1-r3 | — | When asked to both use a .netrc file for credentials an... |
| Medium | CVE-2025-15079 | curl | 8.14.1-r3 | — | When doing SSH-based transfers using either SCP or SFTP, ... |
| Medium | CVE-2026-7168 | curl | 8.14.1-r3 | — | Successfully using libcurl to do a transfer over a specif... |
| Medium | CVE-2026-3784 | curl | 8.14.1-r3 | — | curl would wrongly reuse an existing HTTP proxy connectio... |
| Medium | CVE-2026-3783 | curl | 8.14.1-r3 | — | When an OAuth2 bearer token is used for an HTTP(S) transf... |
| Medium | CVE-2025-10966 | curl | 8.14.1-r3 | — | curl's code for managing SSH connections when SFTP was do... |
| Medium | CVE-2026-4873 | curl | 8.14.1-r3 | — | A vulnerability exists where a connection requiring TLS i... |
| Medium | CVE-2025-60876 | busybox | 1.37.0-r20 | — | BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) ... |
| Medium | CVE-2025-60876 | busybox-binsh | 1.37.0-r20 | — | BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) ... |
| Medium | CVE-2025-60876 | ssl_client | 1.37.0-r20 | — | BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) ... |
| Medium | CVE-2026-1965 | curl | 8.14.1-r3 | — | libcurl can in some circumstances reuse the wrong connect... |
| Medium | CVE-2026-58055 | nghttp2-libs | 1.69.0-r0 | — | nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1... |
| Medium | CVE-2025-13034 | curl | 8.14.1-r3 | — | When using CURLOPT_PINNEDPUBLICKEY option with libcurl ... |
| Medium | CVE-2025-14017 | curl | 8.14.1-r3 | — | When doing multi-threaded LDAPS transfers (LDAP over TLS)... |
| Low | CVE-2025-15224 | curl | 8.14.1-r3 | — | When doing SSH-based transfers using either SCP or SFTP, ... |
Full changelog
- [
e15fef2] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) - [
ec749f0] refresh generated badges (stagefreight) - [
98f9dda] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) - [
173fe4f] refresh generated badges (stagefreight) - [
295476e] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) - [
afdcb8f] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) - [
3ece56e] refresh generated badges (stagefreight) - [
e16ab4e] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) - [
9764a74] refresh generated badges (stagefreight) - [
2332fba] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) - [
e404a97] refresh generated badges (stagefreight) - [
5259eba] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) - [
5fb0cae] refresh generated badges (stagefreight) - [
6b71d86] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) - [
a1a4edc] refresh generated badges (stagefreight) - [
331cc8a] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) - [
c3adb29] refresh generated badges (stagefreight) - [
41cb426] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) - [
8815c9e] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) - [
7dde143] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) - [
83e2395] refresh generated badges (stagefreight) - [
cbd1e41] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) - [
6860706] refresh generated badges (stagefreight) - [
4809079] governance reconcile from PrPlanIT/MaintenancePolicy 11066049d06cb0e071409a80bc96411b0a899d1e (StageFreight) - [
bbecd92] refresh generated badges (stagefreight) - [
b076551] governance reconcile from PrPlanIT/MaintenancePolicy 44ce7931b90a3386783ed4f03a822f98eb8128de (StageFreight) - [
291efd2] refresh generated badges (stagefreight) - [
85e71a2] governance reconcile from PrPlanIT/MaintenancePolicy 2fcb480f6f7c686b6e35251e415249617752757b (StageFreight) - [
ce5916a] refresh generated badges (stagefreight) - [
fbef8ab] governance reconcile from PrPlanIT/MaintenancePolicy be6129b7d6583ac9fc8b2483c0e23fd1c67a5069 (StageFreight) - [
8ebc2fc] refresh generated badges (stagefreight) - [
238d7fa] update managed dependencies (stagefreight) - [
ebdb30e] re-render .gitlab-ci.yml for the governed config (SoFMeRight) - [
f68521d] governance reconcile from PrPlanIT/MaintenancePolicy 643a4fdc2e87ac974407c3864a42f957fa9c56e5 (StageFreight) - [
bf18a4b] rename Readme.md to README.md; add GPL-3.0 LICENSE; retarget image to hlhd/nginx-extras (SoFMeRight) - [
6f3ee73] governance reconcile from PrPlanIT/MaintenancePolicy 814d185bc7dd335963b721170a179791bce141fc (Stage...
Release v0.0.6
PrecisionPlanIT 🌎 — nginx-extras-oci:v0.0.6
Release Highlights
Feat: Alpine version updated to 3.22.2 for the latest security patches.
Notable Changes
Fixes
- fix: release pipeline to add security scan phase. (SoFMeRight)
Images & Artifacts Availability
Assets available: images • SBOM — see links in the Assets box at the top of this release.
Security Status
🛡️ Security Scan: ✅ Passed
No critical or high vulnerabilities detected.
📦 Software Bill of Materials (SBOM) has been generated and attached to container registries where supported.
Installation
- For installation and usage instructions, see the README
Contributing
If you find this useful, you can help:
- Submit a Merge Request with new features or fixes
- Report bugs or issues on Issues
- You can donate funds to help with my operating cost.
Changelog
- [5b7ef93] fix: release pipeline to add security scan phase. (SoFMeRight)
- [69cf3fa] Bump Alpine to 3.22.2 for security patches (SoFMeRight)
Container Images
Release v0.0.5
AntParade GitOps 🐜 - nginx-extras-oci:v0.0.5
Image Availability:
Installation
For installation and usage instructions, please refer to the README
Contributing
If you find this image useful, you can help:
- Submit a Merge Request with new features or fixes
- Report bugs or issues on GitLab Issues
Changelog
- [d1b2dd0] Move health-check to Dockerfile from compose... (SoFMeRight)
Container Images
Release v0.0.4
AntParade GitOps 🐜 - nginx-extras-oci:v0.0.4
Image Availability:
Installation
For installation and usage instructions, please refer to the README
Contributing
If you find this image useful, you can help:
- Submit a Merge Request with new features or fixes
- Report bugs or issues on GitLab Issues
Changelog
- [7aed02a] Refactoring docker-compose, strip out unneeded things in default nginx.conf (SoFMeRight)
- [868e589] This is an update of currently working default nginx.conf after extended diagnostics.. (SoFMeRight)
- [7b90c97] Add last message. (SoFMeRight)
- [a26e3ca] Commit intial Readme. (SoFMeRight)
- [757d220] Non-existent package. (SoFMeRight)
- [b776eeb] Adding nginx-mod-http-grpc 😵💫 (SoFMeRight)
Container Images
Release v0.0.3
AntParade GitOps 🐜 - nginx-extras-oci:v0.0.3
Image Availability:
Installation
For installation and usage instructions, please refer to the README
Contributing
If you find this image useful, you can help:
- Submit a Merge Request with new features or fixes
- Report bugs or issues on GitLab Issues
Changelog
- [f090d36] Update script. (SoFMeRight)
- [225af30] Put the comment back at the top of the nginx.conf (SoFMeRight)
- [5151872] Bake in healthcheck. (SoFMeRight)
- [b858dd3] Refactor and maintain stability. (SoFMeRight)
- [f24b96e] Add container healthcheck .conf. Add docker-compose-example.yaml (SoFMeRight)
- [ce405cb] Add a default nginx.conf to the repository. (SoFMeRight)
- [4a86eef] Add default nginx.conf example. (SoFMeRight)
Container Images
Release v0.0.2
AntParade GitOps 🐜 - nginx-extras-oci:v0.0.2
Image Availability:
Installation
For installation and usage instructions, please refer to the README
Contributing
If you find this image useful, you can help:
- Submit a Merge Request with new features or fixes
- Report bugs or issues on GitLab Issues
Changelog
- [0214d65] Add entrypoint script. (SoFMeRight)
Container Images
Release v0.0.1
AntParade GitOps 🐜 - nginx-extras-oci:v0.0.1
- Cloudflare wildcards
Image Availability:
Installation
For installation and usage instructions, please refer to the README
Contributing
If you find this image useful, you can help:
- Submit a Merge Request with new features or fixes
- Report bugs or issues on GitLab Issues
Changelog
- [cdff133] Fix: What was I doing??! Wrong from label.. (SoFMeRight)
- [bf6d3a8] Pin proper alpine image... ... (SoFMeRight)
- [a83755e] Pin the image to 3.13.7-alpine3.22. (SoFMeRight)