#1454 |
ngx_palloc may return a heap-buffer-overflow address if the parameter size is not aligned when call ngx_create_pool
|
|
defect
|
minor
|
|
other
|
#1462 |
Logging directory is always /var/log on startup
|
|
defect
|
minor
|
|
nginx-core
|
#1468 |
408 generated during active transfer to upstream
|
|
defect
|
minor
|
|
other
|
#1470 |
ssl_protocols is not overwrited by specific "per-server" value
|
|
defect
|
minor
|
|
other
|
#1484 |
Timeouts when proxying to Apache and using Keepalive
|
|
defect
|
major
|
|
other
|
#1490 |
NGINX hold request too long, and causes timeout error.
|
|
defect
|
major
|
|
nginx-core
|
#1493 |
nginx proxy + cloudflare + https = 403 Forbidden cloudflare-nginx
|
|
defect
|
major
|
|
other
|
#1498 |
Named and capture variables cannot be used together
|
|
defect
|
minor
|
|
nginx-module
|
#1507 |
gzip in if + proxy_pass doesn't work
|
|
defect
|
minor
|
|
nginx-core
|
#1508 |
When browser access nginx http/2 server with large cookies, nginx don't return HTTP4xx but return http/2 ENHANCE YOUR CALM error.
|
|
defect
|
major
|
|
nginx-core
|
#1526 |
Absolute redirect auto-triggered by location does not include port from Host header
|
|
defect
|
minor
|
|
other
|
#1532 |
nginx not build on fedora28
|
|
defect
|
major
|
|
nginx-core
|
#1556 |
nginx doesn't build due to missing 'current_salt' in 'crypt_data' struct
|
|
defect
|
minor
|
|
other
|
#1561 |
HTTP/2 without SSL not working
|
|
defect
|
minor
|
|
nginx-core
|
#1567 |
SystemD reload swallows error messages
|
|
defect
|
minor
|
|
other
|
#1569 |
gzip_static always does not work with try_files when no uncompressed file
|
|
defect
|
minor
|
|
other
|
#1575 |
use "font/woff" and "font/woff2" in file "mime.types"
|
|
defect
|
minor
|
|
nginx-core
|
#1581 |
Build issue in GCC
|
|
defect
|
minor
|
|
nginx-core
|
#1583 |
nginx cannot run as a regular user
|
|
defect
|
minor
|
|
other
|
#1585 |
ssl_verify_client cause core dump
|
|
defect
|
blocker
|
nginx-1.15
|
nginx-core
|
#1589 |
realip module's effective level
|
|
defect
|
minor
|
|
other
|
#1592 |
"nginx -s" doesn't read error_log configuration
|
|
defect
|
minor
|
|
nginx-core
|
#1596 |
$body_bytes_sent larger than acutual body size when chunked enabled
|
|
defect
|
minor
|
|
other
|
#1601 |
ssl default server must have a cert even if it's not being accessed
|
|
defect
|
minor
|
|
nginx-core
|
#1610 |
Writing connections counter leak in stub_status.
|
|
defect
|
major
|
|
other
|
#1611 |
Compile error (Werror=incompatible-pointer-types) with LibreSSL 2.8.0
|
|
defect
|
minor
|
|
other
|
#1614 |
proxy cache 404 STALE forever
|
|
defect
|
minor
|
|
other
|
#1620 |
gzip_static not work with index file
|
|
defect
|
minor
|
|
nginx-module
|
#1621 |
gzip_static not work with index file
|
|
defect
|
minor
|
|
nginx-module
|
#1622 |
gzip_static not work with index file
|
|
defect
|
minor
|
|
nginx-module
|
#1647 |
Evaluation of multiple regexes brakes back references
|
|
defect
|
major
|
|
nginx-core
|
#1655 |
Nginx does not use Proxy??
|
|
defect
|
minor
|
|
other
|
#1670 |
Chipers list order not respected for TLS 1.3
|
|
defect
|
major
|
nginx-1.15
|
nginx-core
|
#1685 |
Update fonts mime types refer to IANA
|
|
defect
|
minor
|
|
other
|
#1707 |
try_files doesn't work sometimes
|
|
defect
|
minor
|
nginx-1.15
|
nginx-core
|
#1712 |
xfs - nginx cache manager wrongly calculates cache size
|
|
defect
|
major
|
|
other
|
#1714 |
Server Name Indication (SNI) in NGINX isn't honoring ssl_protocols, ssl_ciphers etc. per server{} config / TLS downgrade and server exhaustion attack.
|
|
defect
|
critical
|
|
nginx-core
|
#1728 |
Parsing HTTP request is wrong
|
|
defect
|
minor
|
|
other
|
#1749 |
HTTP/2 broken connection on requests with URI > 5k
|
|
defect
|
minor
|
|
other
|
#1755 |
listen address and http2
|
|
defect
|
minor
|
|
nginx-core
|
#1758 |
CLI test configuration does not detect error within index directive
|
|
defect
|
minor
|
|
nginx-package
|
#1762 |
Duplicated headers not being passed to backend proxy
|
|
defect
|
minor
|
|
other
|
#1779 |
ngx_reset_pool() function make (sizeof(ngx_pool_t) - sizeof(ngx_pool_data_t) ) bytes memory unavailable
|
|
defect
|
minor
|
|
nginx-core
|
#1791 |
Nginx -t changing ownersip of cache path
|
|
defect
|
critical
|
nginx-1.17.1
|
nginx-core
|
#1800 |
nginx close http2 connection if request too large
|
|
defect
|
minor
|
|
other
|
#1802 |
Bad response for request with large cookie via http2
|
|
defect
|
critical
|
unit-1.10
|
nginx-core
|
#1827 |
Enabling http2 for one server block enables it for all
|
|
defect
|
minor
|
|
nginx-module
|
#1828 |
Cookies with 2-digit years in their expires value
|
|
defect
|
minor
|
|
other
|
#1830 |
OCSP must staple fails with multi-domain certificates
|
|
defect
|
major
|
|
nginx-core
|
#1832 |
Occasionally get "...zero size buf in writer..."
|
|
defect
|
major
|
|
other
|
#1836 |
limit_req and proxy_pass
|
|
defect
|
minor
|
|
nginx-core
|
#1839 |
Add new config/option for OpenSSL 1.1.1 / TLS 1.3
|
|
defect
|
major
|
nginx-1.17
|
other
|
#1851 |
nginx Http2 Push fails when Vary: Accept header set
|
|
defect
|
major
|
|
nginx-package
|
#1853 |
grpc_pass not parsing set variables
|
|
defect
|
critical
|
|
nginx-module
|
#1854 |
Connection Reset due to "unexpected range in slice response" error
|
|
defect
|
major
|
|
other
|
#1862 |
Cache-Control:no-store should remove entry from cache (with proxy_cache_background_update+proxy_cache_use_stale)
|
|
defect
|
minor
|
|
other
|
#1866 |
nginx does not log error if packet exceeds http2_max_field_size
|
|
defect
|
minor
|
|
nginx-module
|
#1874 |
Nginux 1.16/1.17 Perl Module Fails Ubuntu 18
|
|
defect
|
major
|
nginx-1.17
|
nginx-core
|
#1878 |
Set ciphersuite list order for TLS 1.3
|
|
defect
|
major
|
nginx-1.17
|
nginx-core
|
#1880 |
nginx should bypass cache if worker failed to allocate node in cache keys zone
|
|
defect
|
minor
|
|
other
|
#1898 |
Owner of directories *_temp changed when tested config
|
|
defect
|
minor
|
|
other
|
#1907 |
Nginx does not handle URL larger than 8K
|
|
defect
|
major
|
|
nginx-core
|
#1910 |
http2_push not pushing the file
|
|
defect
|
minor
|
|
nginx-module
|
#1915 |
Potential Memory Leak in directory 'src/event'. file 'ngx_event_openssl_stapling.c'
|
|
defect
|
minor
|
|
other
|
#1916 |
Potential Memory Leak in directory 'src/http/modules'. file 'ngx_http_auth_request_module.c'
|
|
defect
|
minor
|
|
nginx-module
|
#1917 |
Potential Memory Leak in directory 'src/core'. file 'ngx_hash.c.patch'
|
|
defect
|
minor
|
|
nginx-core
|
#1918 |
Potential Memory Leak in directory 'src/http/modules'. file 'ngx_http_auth_request_module.c'
|
|
defect
|
minor
|
|
nginx-module
|
#1919 |
Potential Memory Leak in directory 'src/core'. file 'ngx_hash.c.patch'
|
|
defect
|
minor
|
|
nginx-core
|
#1920 |
Potential Memory Leak in directory 'src/http/modules'. file 'ngx_http_fastcgi_module.c'
|
|
defect
|
minor
|
|
nginx-module
|
#1921 |
Potential Memory Leak in directory 'src/http/modules'. file 'ngx_http_flv_module.c.patch'
|
|
defect
|
minor
|
|
nginx-module
|
#1922 |
Potential Memory Leak in directory 'src/http/modules'. file 'ngx_http_grpc_module.c'
|
|
defect
|
minor
|
|
nginx-module
|
#1923 |
Potential Memory Leak in directory 'src/core'. file 'ngx_inet.c'
|
|
defect
|
minor
|
|
nginx-core
|
#1924 |
10GB localhost download stalls
|
|
defect
|
major
|
|
nginx-core
|
#1933 |
nginx -t does not write to set error log
|
|
defect
|
minor
|
|
documentation
|
#1934 |
Unpredictable behaviour using proxy_cookie_path to add SameSite cookie attribute
|
|
defect
|
critical
|
|
documentation
|
#1940 |
NGINX CONF
|
|
defect
|
minor
|
|
other
|
#1948 |
The directive 'ssl_protocols' is invalid ?
|
|
defect
|
minor
|
|
nginx-module
|
#1952 |
systemd[1]: nginx.service: Failed to parse PID from file /run/nginx.pid: Invalid argument
|
|
defect
|
minor
|
|
nginx-core
|
#1966 |
MKCOL refuses creation without trailing slash
|
|
defect
|
minor
|
|
nginx-module
|
#1967 |
Cannot use different SSL protocols in different server blocks
|
|
defect
|
major
|
|
nginx-core
|
#1968 |
Cannot use different SSL protocols in different server blocks
|
|
defect
|
major
|
|
nginx-core
|
#1970 |
ssl_ecdh_curve avoid 0-RTT
|
|
defect
|
major
|
|
nginx-core
|
#1973 |
Intermittent form body loss with concurrent HTTP2 POST requests
|
|
defect
|
minor
|
|
nginx-core
|
#1979 |
listen 80 http2; combined with proxy_pass http:// brakes website
|
|
defect
|
minor
|
|
nginx-core
|
#1983 |
nginx.service unit-file in rpm (CentOS 7,8)
|
|
defect
|
minor
|
|
nginx-package
|
#1985 |
No header response in 400 Bad Request
|
|
defect
|
major
|
unit-1.18
|
nginx-core
|
#1998 |
SSL Stapling not preloading OCSP answer
|
|
defect
|
minor
|
|
nginx-module
|
#1999 |
Fix webdav unable to rename folders and create folders
|
|
defect
|
critical
|
|
nginx-module
|
#2005 |
nginx closes connection instead of returning proper error code (like 414) when http2 is enabled and too long url is provided
|
|
defect
|
minor
|
|
nginx-core
|
#2007 |
HTTP2 directive from one "server" passed to another
|
|
defect
|
minor
|
|
documentation
|
#2011 |
confusing stderr message 'could not open error log file: open() "/var/log/nginx/error.log"' even if not using default error_log location
|
|
defect
|
minor
|
|
nginx-core
|
#2015 |
Directive 'ssl_protocols' doesn't work on server blocks
|
|
defect
|
minor
|
|
nginx-core
|
#2016 |
nginx does not percent-encode Location header properly
|
|
defect
|
minor
|
|
nginx-module
|
#2036 |
Can't get old SSL cert to work - ca md too weak
|
|
defect
|
minor
|
|
nginx-core
|
#2037 |
Can't get old SSL cert to work - ca md too weak
|
|
defect
|
minor
|
|
nginx-core
|
#2038 |
Can't get old SSL cert to work - ca md too weak
|
|
defect
|
minor
|
|
nginx-core
|
#2039 |
Can't get old SSL cert to work - ca md too weak
|
|
defect
|
minor
|
|
nginx-core
|
#2040 |
Can't get old SSL cert to work - ca md too weak
|
|
defect
|
minor
|
|
nginx-core
|
#2041 |
Can't get old SSL cert to work - ca md too weak
|
|
defect
|
minor
|
|
nginx-core
|
#2042 |
Can't get old SSL cert to work - ca md too weak
|
|
defect
|
minor
|
|
nginx-core
|