CVE-2026-40701: use-after-free in DNS with ssl_ocsp (1.31.0)
Operator Action Required
nginx 1.31.x breaking change: HTTP/2 and HTTP/3 requests with hop-by-hop headers (Connection, Proxy-Connection, Keep-Alive, Transfer-Encoding, Upgrade) are now rejected. This is correct HTTP/2 behavior per RFC 7540 §8.1.2.2 and affects only non-conformant clients. Standard browsers and well-behaved proxies are unaffected. No config changes needed for this recipe.
Recipe version bump
0.8.0+v0.18.0 → 0.9.0+v0.18.0 (minor bump due to nginx minor version with breaking change)
Tested green on the cc-ci recipe CI server (full suite, cold, against this PR head). NOT merged — for operator review.
## Upgrade lasuite-drive to 0.9.0+v0.18.0
### Image tag changes
| service | image | current | new |
|---------|-------|---------|-----|
| redis | redis | 8.6.3 | 8.6.4 |
| web | nginx | 1.30.0 | 1.31.1 |
### redis 8.6.4 (patch — HIGH urgency bug fixes)
- No breaking changes or migrations required
- 16 critical bug fixes including: AArch64 startup fix, cluster crash prevention, XREADGROUP stream replication consistency, Sentinel config injection security patch, integer overflow in SCAN COUNT, TCP deadlock prevention
### nginx 1.31.1 (minor — multiple security CVE fixes)
- CVE-2026-9256: heap buffer overflow in ngx_http_rewrite_module (1.31.1)
- CVE-2026-42926, CVE-2026-42945, CVE-2026-42946, CVE-2026-42934: various buffer overflow/overread fixes (1.31.0)
- CVE-2026-40460: HTTP/3 connection migration address spoofing (1.31.0)
- CVE-2026-40701: use-after-free in DNS with ssl_ocsp (1.31.0)
### Operator Action Required
**nginx 1.31.x breaking change:** HTTP/2 and HTTP/3 requests with hop-by-hop headers (Connection, Proxy-Connection, Keep-Alive, Transfer-Encoding, Upgrade) are now rejected. This is correct HTTP/2 behavior per RFC 7540 §8.1.2.2 and affects only non-conformant clients. Standard browsers and well-behaved proxies are unaffected. No config changes needed for this recipe.
### Recipe version bump
0.8.0+v0.18.0 → 0.9.0+v0.18.0 (minor bump due to nginx minor version with breaking change)
Tested green on the cc-ci recipe CI server (full suite, cold, against this PR head). NOT merged — for operator review.
cc @trav @notplants
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Upgrade lasuite-drive to 0.9.0+v0.18.0
Image tag changes
redis 8.6.4 (patch — HIGH urgency bug fixes)
nginx 1.31.1 (minor — multiple security CVE fixes)
Operator Action Required
nginx 1.31.x breaking change: HTTP/2 and HTTP/3 requests with hop-by-hop headers (Connection, Proxy-Connection, Keep-Alive, Transfer-Encoding, Upgrade) are now rejected. This is correct HTTP/2 behavior per RFC 7540 §8.1.2.2 and affects only non-conformant clients. Standard browsers and well-behaved proxies are unaffected. No config changes needed for this recipe.
Recipe version bump
0.8.0+v0.18.0 → 0.9.0+v0.18.0 (minor bump due to nginx minor version with breaking change)
Tested green on the cc-ci recipe CI server (full suite, cold, against this PR head). NOT merged — for operator review.
cc @trav @notplants
!testme
🌻 cc-ci —
lasuite-drive@ffa7d585✅ passedfull logs · dashboard
Pull request closed