dev-e15fef2
Pre-release
Pre-release
π¦ nginx-extras β v0.0.6-dev+e15fef2
Release type: prerelease β’ Commit:
e15fef2
Security: π‘οΈ β Critical β 6 critical and 9 high vulnerabilities detected
Image Availability
| Registry | Image | Tags |
|---|---|---|
| Docker Hub | docker.io/hlhd/nginx-extras |
dev-e15fef2 latest-dev |
| cr.pcfae.com | cr.pcfae.com/hlhd/nginx-extras |
dev-e15fef2 latest-dev |
| GitHub Container Registry | ghcr.io/homelabhd/nginx-extras |
dev-e15fef2 latest-dev |
Digest pull commands & supply chain artifacts
docker.io/hlhd/nginx-extras
docker pull docker.io/hlhd/nginx-extras@sha256:8bd9e934ec5ed79062c5f821a9ea52f1228d753c4193436cd01a0e3cdb36a2da
cr.pcfae.com/hlhd/nginx-extras
docker pull cr.pcfae.com/hlhd/nginx-extras@sha256:8bd9e934ec5ed79062c5f821a9ea52f1228d753c4193436cd01a0e3cdb36a2da
ghcr.io/homelabhd/nginx-extras
docker pull ghcr.io/homelabhd/nginx-extras@sha256:8bd9e934ec5ed79062c5f821a9ea52f1228d753c4193436cd01a0e3cdb36a2da
Notable Changes
Documentation
- refresh generated badges (stagefreight) Γ14
Maintenance
- governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) Γ13
- governance reconcile from PrPlanIT/MaintenancePolicy 11066049d06cb0e071409a80bc96411b0a899d1e (StageFreight)
- governance reconcile from PrPlanIT/MaintenancePolicy 44ce7931b90a3386783ed4f03a822f98eb8128de (StageFreight)
- governance reconcile from PrPlanIT/MaintenancePolicy 2fcb480f6f7c686b6e35251e415249617752757b (StageFreight)
- governance reconcile from PrPlanIT/MaintenancePolicy be6129b7d6583ac9fc8b2483c0e23fd1c67a5069 (StageFreight)
- deps: update managed dependencies (stagefreight)
- re-render .gitlab-ci.yml for the governed config (SoFMeRight)
- governance reconcile from PrPlanIT/MaintenancePolicy 643a4fdc2e87ac974407c3864a42f957fa9c56e5 (StageFreight)
- rename Readme.md to README.md; add GPL-3.0 LICENSE; retarget image to hlhd/nginx-extras (SoFMeRight)
- governance reconcile from PrPlanIT/MaintenancePolicy 814d185bc7dd335963b721170a179791bce141fc (StageFreight)
Security
π‘οΈ β Critical β 6 critical and 9 high vulnerabilities detected
Vulnerability details (6 critical, 9 high, 18 medium, 1 low)
| Severity | CVE | Package | Installed | Fixed | Description |
|---|---|---|---|---|---|
| Critical | CVE-2026-9079 | curl | 8.14.1-r3 | β | libcurl had a flaw that when instructed to clear proxy au... |
| Critical | CVE-2026-10536 | curl | 8.14.1-r3 | β | A use-after-free vulnerability exists in libcurl when an ... |
| Critical | CVE-2026-11856 | curl | 8.14.1-r3 | β | Successfully using libcurl to do a transfer to a specific... |
| Critical | CVE-2026-8924 | curl | 8.14.1-r3 | β | A flaw in curlβs cookie parsing logic allows a maliciou... |
| Critical | CVE-2026-8927 | curl | 8.14.1-r3 | β | When reusing a libcurl handle for sequential transfers dr... |
| Critical | CVE-2026-8926 | curl | 8.14.1-r3 | β | When asking curl to use a .netrc file to find credentia... |
| High | CVE-2026-3805 | curl | 8.14.1-r3 | β | When doing a second SMB request to the same host again, c... |
| High | CVE-2026-5773 | curl | 8.14.1-r3 | β | libcurl might in some circumstances reuse the wrong conne... |
| High | CVE-2026-12064 | curl | 8.14.1-r3 | β | When a user invokes curl using a schemeless URL combined ... |
| High | CVE-2026-8932 | curl | 8.14.1-r3 | β | libcurl would reuse a previously created connection even ... |
| High | CVE-2026-9547 | curl | 8.14.1-r3 | β | When a libcurl-based application performs transfers via `... |
| High | CVE-2026-8286 | curl | 8.14.1-r3 | β | A vulnerability exists where a new transfer that uses STA... |
| High | CVE-2026-6276 | curl | 8.14.1-r3 | β | Using libcurl, when a custom Host: header is first set ... |
| High | CVE-2026-9080 | curl | 8.14.1-r3 | β | Calling curl_easy_pause() within the event-based `CURLM... |
| High | CVE-2026-9545 | curl | 8.14.1-r3 | β | In this scenario, libcurl first uses a proper HTTP/3 serv... |
| Medium | CVE-2026-6253 | curl | 8.14.1-r3 | β | curl might erroneously pass on credentials for a first pr... |
| Medium | CVE-2025-14819 | curl | 8.14.1-r3 | β | When doing TLS related transfers with reused easy or mult... |
| Medium | CVE-2025-14524 | curl | 8.14.1-r3 | β | When an OAuth2 bearer token is used for an HTTP(S) transf... |
| Medium | CVE-2026-8458 | curl | 8.14.1-r3 | β | libcurl might in some circumstances reuse the wrong conne... |
| Medium | CVE-2026-6429 | curl | 8.14.1-r3 | β | When asked to both use a .netrc file for credentials an... |
| Medium | CVE-2025-15079 | curl | 8.14.1-r3 | β | When doing SSH-based transfers using either SCP or SFTP, ... |
| Medium | CVE-2026-7168 | curl | 8.14.1-r3 | β | Successfully using libcurl to do a transfer over a specif... |
| Medium | CVE-2026-3784 | curl | 8.14.1-r3 | β | curl would wrongly reuse an existing HTTP proxy connectio... |
| Medium | CVE-2026-3783 | curl | 8.14.1-r3 | β | When an OAuth2 bearer token is used for an HTTP(S) transf... |
| Medium | CVE-2025-10966 | curl | 8.14.1-r3 | β | curl's code for managing SSH connections when SFTP was do... |
| Medium | CVE-2026-4873 | curl | 8.14.1-r3 | β | A vulnerability exists where a connection requiring TLS i... |
| Medium | CVE-2025-60876 | busybox | 1.37.0-r20 | β | BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) ... |
| Medium | CVE-2025-60876 | busybox-binsh | 1.37.0-r20 | β | BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) ... |
| Medium | CVE-2025-60876 | ssl_client | 1.37.0-r20 | β | BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) ... |
| Medium | CVE-2026-1965 | curl | 8.14.1-r3 | β | libcurl can in some circumstances reuse the wrong connect... |
| Medium | CVE-2026-58055 | nghttp2-libs | 1.69.0-r0 | β | nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1... |
| Medium | CVE-2025-13034 | curl | 8.14.1-r3 | β | When using CURLOPT_PINNEDPUBLICKEY option with libcurl ... |
| Medium | CVE-2025-14017 | curl | 8.14.1-r3 | β | When doing multi-threaded LDAPS transfers (LDAP over TLS)... |
| Low | CVE-2025-15224 | curl | 8.14.1-r3 | β | When doing SSH-based transfers using either SCP or SFTP, ... |
Full changelog
- [
e15fef2] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) - [
ec749f0] refresh generated badges (stagefreight) - [
98f9dda] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) - [
173fe4f] refresh generated badges (stagefreight) - [
295476e] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) - [
afdcb8f] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) - [
3ece56e] refresh generated badges (stagefreight) - [
e16ab4e] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) - [
9764a74] refresh generated badges (stagefreight) - [
2332fba] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) - [
e404a97] refresh generated badges (stagefreight) - [
5259eba] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) - [
5fb0cae] refresh generated badges (stagefreight) - [
6b71d86] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) - [
a1a4edc] refresh generated badges (stagefreight) - [
331cc8a] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) - [
c3adb29] refresh generated badges (stagefreight) - [
41cb426] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) - [
8815c9e] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) - [
7dde143] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) - [
83e2395] refresh generated badges (stagefreight) - [
cbd1e41] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) - [
6860706] refresh generated badges (stagefreight) - [
4809079] governance reconcile from PrPlanIT/MaintenancePolicy 11066049d06cb0e071409a80bc96411b0a899d1e (StageFreight) - [
bbecd92] refresh generated badges (stagefreight) - [
b076551] governance reconcile from PrPlanIT/MaintenancePolicy 44ce7931b90a3386783ed4f03a822f98eb8128de (StageFreight) - [
291efd2] refresh generated badges (stagefreight) - [
85e71a2] governance reconcile from PrPlanIT/MaintenancePolicy 2fcb480f6f7c686b6e35251e415249617752757b (StageFreight) - [
ce5916a] refresh generated badges (stagefreight) - [
fbef8ab] governance reconcile from PrPlanIT/MaintenancePolicy be6129b7d6583ac9fc8b2483c0e23fd1c67a5069 (StageFreight) - [
8ebc2fc] refresh generated badges (stagefreight) - [
238d7fa] update managed dependencies (stagefreight) - [
ebdb30e] re-render .gitlab-ci.yml for the governed config (SoFMeRight) - [
f68521d] governance reconcile from PrPlanIT/MaintenancePolicy 643a4fdc2e87ac974407c3864a42f957fa9c56e5 (StageFreight) - [
bf18a4b] rename Readme.md to README.md; add GPL-3.0 LICENSE; retarget image to hlhd/nginx-extras (SoFMeRight) - [
6f3ee73] governance reconcile from PrPlanIT/MaintenancePolicy 814d185bc7dd335963b721170a179791bce141fc (StageFreight)