Security — CVE-2026-90439: a heap memory buffer overflow might occur in a worker process under certain configurations when using HTTP/3 with OpenSSL 3.5.0 and earlier (F5 advisory K000162604: Medium, CVSS v3.1 6.5 / v4.0 6.9; NGINX Open Source 1.29.2–1.31.5 vulnerable, fixed in 1.31.6). Not exploitable in this recipe's shape (plain HTTP/1.1 static serving on :80 behind traefik, no HTTP/3/QUIC listener) — but the bump ships the fix.
Change: the QUIC transport parameters extension received in an SSL connection is now always ignored.
Bugfixes: binary upgrade with control API socket + perl module; predicate-location evaluation error no longer ignored; nested location lookup with regex/predicate locations; segfault reading config with geo + ranges and a corrupted binary base file.
Advisory scan (deterministic + adjudicated): 1 CVE fixed by this window — CVE-2026-90439 (the release notes name no other).
None. Tag-only bump; no config/env/volume/label changes; no migrations. None of the 1.31.6 changes touch this recipe's config surface (static file serving, no HTTP/3, no proxy upstreams, no perl/geo/predicate locations).
Release
The coop-cloud.${STACK_NAME}.version label (1.14.0+1.31.5) is intentionally NOT bumped in this PR; it is set at release time. After this merges:
abra recipe release custom-html -z
Tested green on the cc-ci recipe CI server (full suite, cold, against this PR head). NOT merged — for operator review.
Bumps the **nginx** app image 1.31.5 → 1.31.6 (nginx mainline, 15 Sep 2026 — a security patch release).
## Image tags
| service | image | current | new |
|---------|-------|---------|-----|
| app | nginx | 1.31.5 | 1.31.6 |
Sidecars unchanged: `alpine/git v2.54.0` (latest per abra), `linuxserver/openssh-server` `latest` (intended floating tag).
## Why
- **Security — CVE-2026-90439**: a heap memory buffer overflow might occur in a worker process under certain configurations when using HTTP/3 with OpenSSL 3.5.0 and earlier (F5 advisory K000162604: Medium, CVSS v3.1 6.5 / v4.0 6.9; NGINX Open Source 1.29.2–1.31.5 vulnerable, fixed in 1.31.6). Not exploitable in this recipe's shape (plain HTTP/1.1 static serving on :80 behind traefik, no HTTP/3/QUIC listener) — but the bump ships the fix.
- Change: the QUIC transport parameters extension received in an SSL connection is now always ignored.
- Bugfixes: binary upgrade with control API socket + perl module; predicate-location evaluation error no longer ignored; nested location lookup with regex/predicate locations; segfault reading config with `geo` + `ranges` and a corrupted binary base file.
Advisory scan (deterministic + adjudicated): **1 CVE fixed by this window** — CVE-2026-90439 (the release notes name no other).
**Upstream release notes:** app nginx 1.31.5→1.31.6: https://nginx.org/en/CHANGES
## Operator action required
**None.** Tag-only bump; no config/env/volume/label changes; no migrations. None of the 1.31.6 changes touch this recipe's config surface (static file serving, no HTTP/3, no proxy upstreams, no perl/geo/predicate locations).
## Release
The `coop-cloud.${STACK_NAME}.version` label (1.14.0+1.31.5) is intentionally NOT bumped in this PR; it is set at release time. After this merges:
abra recipe release custom-html -z
Tested green on the cc-ci recipe CI server (full suite, cold, against this PR head). NOT merged — for operator review.
cc @trav @notplants
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Bumps the nginx app image 1.31.5 → 1.31.6 (nginx mainline, 15 Sep 2026 — a security patch release).
Image tags
Sidecars unchanged:
alpine/git v2.54.0(latest per abra),linuxserver/openssh-serverlatest(intended floating tag).Why
geo+rangesand a corrupted binary base file.Advisory scan (deterministic + adjudicated): 1 CVE fixed by this window — CVE-2026-90439 (the release notes name no other).
Upstream release notes: app nginx 1.31.5→1.31.6: https://nginx.org/en/CHANGES
Operator action required
None. Tag-only bump; no config/env/volume/label changes; no migrations. None of the 1.31.6 changes touch this recipe's config surface (static file serving, no HTTP/3, no proxy upstreams, no perl/geo/predicate locations).
Release
The
coop-cloud.${STACK_NAME}.versionlabel (1.14.0+1.31.5) is intentionally NOT bumped in this PR; it is set at release time. After this merges:abra recipe release custom-html -z
Tested green on the cc-ci recipe CI server (full suite, cold, against this PR head). NOT merged — for operator review.
cc @trav @notplants
!testme
🌻 cc-ci —
custom-html@4e5976f6✅ passedfull logs · dashboard
Auto-closed by cc-ci canonical sweep: its changes are already in upstream main (merged upstream); mirror main re-synced
Pull request closed