nginx 1.x — End of Life
Active High risk23 releases in this series21 CVEs
nginx 1.x — All releases
| Version | Released | Active support | EOL date | Latest patch | Status | Alert me |
|---|---|---|---|---|---|---|
| 1.31 | May 13, 2026 | — | No | 1.31.3 | Active | |
| 1.30 | Apr 14, 2026 | — | No | 1.30.4 | Active | |
| 1.29 | Jun 24, 2025 | — | May 13, 2026 | 1.29.8 | EOL | |
| 1.28 | Apr 23, 2025 | — | Apr 14, 2026 | 1.28.3 | EOL | |
| 1.27 | May 28, 2024 | — | Jun 24, 2025 | 1.27.5 | EOL | |
| 1.26 | Apr 23, 2024 | — | Apr 23, 2025 | 1.26.3 | EOL | |
| 1.25 | May 23, 2023 | — | May 29, 2024 | 1.25.5 | EOL | |
| 1.24 | Apr 11, 2023 | — | Apr 23, 2024 | 1.24.0 | EOL | |
| 1.23 | Jun 21, 2022 | — | May 23, 2023 | 1.23.4 | EOL | |
| 1.22 | May 24, 2022 | — | Apr 11, 2023 | 1.22.1 | EOL | |
| 1.21 | May 25, 2021 | — | Jun 21, 2022 | 1.21.6 | EOL | |
| 1.20 | Apr 20, 2021 | — | May 24, 2022 | 1.20.2 | EOL | |
| 1.19 | May 26, 2020 | — | May 25, 2021 | 1.19.10 | EOL | |
| 1.18 | Apr 21, 2020 | — | Apr 20, 2021 | 1.18.0 | EOL | |
| 1.16 | Apr 23, 2019 | — | Apr 20, 2020 | 1.16.1 | EOL | |
| 1.14 | Apr 17, 2018 | — | Apr 23, 2019 | 1.14.2 | EOL | |
| 1.12 | Apr 12, 2017 | — | Apr 17, 2018 | 1.12.2 | EOL | |
| 1.10 | Apr 26, 2016 | — | Apr 12, 2017 | 1.10.3 | EOL | |
| 1.8 | Apr 21, 2015 | — | Apr 26, 2016 | 1.8.1 | EOL | |
| 1.6 | Apr 24, 2014 | — | Apr 21, 2015 | 1.6.3 | EOL | |
| 1.4 | Apr 24, 2013 | — | Apr 24, 2014 | 1.4.7 | EOL | |
| 1.2 | Apr 23, 2012 | — | Apr 24, 2013 | 1.2.9 | EOL | |
| 1.0 | Apr 12, 2011 | — | Apr 23, 2012 | 1.0.15 | EOL |
CVEs affecting nginx 1.x (21)
| CVE | Severity | CVSS | EPSS | KEV | Cycle | Description | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-49975 | HIGH | 7.5 | 27.98% | — | 1.6 | Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service vi… | Jun 8, 2026 |
| CVE-2026-49975 | HIGH | 7.5 | 27.98% | — | 1.18 | Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service vi… | Jun 8, 2026 |
| CVE-2026-49975 | HIGH | 7.5 | 27.98% | — | 1.25 | Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service vi… | Jun 8, 2026 |
| CVE-2026-49975 | HIGH | 7.5 | 27.98% | — | 1.0 | Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service vi… | Jun 8, 2026 |
| CVE-2026-49975 | HIGH | 7.5 | 27.98% | — | 1.21 | Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service vi… | Jun 8, 2026 |
| CVE-2026-49975 | HIGH | 7.5 | 27.98% | — | 1.29 | Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service vi… | Jun 8, 2026 |
| CVE-2026-49975 | HIGH | 7.5 | 27.98% | — | 1.27 | Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service vi… | Jun 8, 2026 |
| CVE-2026-49975 | HIGH | 7.5 | 27.98% | — | 1.14 | Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service vi… | Jun 8, 2026 |
| CVE-2026-49975 | HIGH | 7.5 | 27.98% | — | 1.24 | Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service vi… | Jun 8, 2026 |
| CVE-2026-49975 | HIGH | 7.5 | 27.98% | — | 1.2 | Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service vi… | Jun 8, 2026 |
| CVE-2026-49975 | HIGH | 7.5 | 27.98% | — | 1.26 | Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service vi… | Jun 8, 2026 |
| CVE-2026-49975 | HIGH | 7.5 | 27.98% | — | 1.16 | Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service vi… | Jun 8, 2026 |
| CVE-2026-49975 | HIGH | 7.5 | 27.98% | — | 1.22 | Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service vi… | Jun 8, 2026 |
| CVE-2026-49975 | HIGH | 7.5 | 27.98% | — | 1.20 | Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service vi… | Jun 8, 2026 |
| CVE-2026-49975 | HIGH | 7.5 | 27.98% | — | 1.10 | Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service vi… | Jun 8, 2026 |
| CVE-2026-49975 | HIGH | 7.5 | 27.98% | — | 1.12 | Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service vi… | Jun 8, 2026 |
| CVE-2026-49975 | HIGH | 7.5 | 27.98% | — | 1.8 | Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service vi… | Jun 8, 2026 |
| CVE-2026-49975 | HIGH | 7.5 | 27.98% | — | 1.4 | Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service vi… | Jun 8, 2026 |
| CVE-2026-49975 | HIGH | 7.5 | 27.98% | — | 1.23 | Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service vi… | Jun 8, 2026 |
| CVE-2026-49975 | HIGH | 7.5 | 27.98% | — | 1.19 | Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service vi… | Jun 8, 2026 |
| CVE-2026-49975 | HIGH | 7.5 | 27.98% | — | 1.28 | Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service vi… | Jun 8, 2026 |
Frequently asked questions
Is nginx 1 end of life?
Partially. Some nginx 1.x releases have reached EOL. Check the version table above for the exact status of each sub-release.
What CVEs affect nginx 1?
There are 21 CVEs tracked for nginx 1.x. See the full list above with CVSS and EPSS scores.
What is the latest nginx 1 version?
The latest nginx 1.x patch release is 1.31.3, released on July 15, 2026. Always run the latest patch to benefit from all security fixes.
When was nginx 1 first released?
nginx 1.0 was initially released on May 13, 2026. See the full version timeline in the table above.
Is it safe to run nginx 1 in production?
nginx 1 is still supported and safe for production use. Ensure you are running the latest patch version (1.31.3) to have all security fixes applied.
Data sourced from endoflife.date · CVE data from NVD · EPSS from FIRST.org · KEV from CISA
