nginx 1.x — End of Life

Active High risk
23 releases in this series21 CVEs

nginx 1.x — All releases

VersionReleasedActive supportEOL dateLatest patchStatusAlert me
1.31May 13, 2026No1.31.3Active
1.30Apr 14, 2026No1.30.4Active
1.29Jun 24, 2025May 13, 20261.29.8EOL
1.28Apr 23, 2025Apr 14, 20261.28.3EOL
1.27May 28, 2024Jun 24, 20251.27.5EOL
1.26Apr 23, 2024Apr 23, 20251.26.3EOL
1.25May 23, 2023May 29, 20241.25.5EOL
1.24Apr 11, 2023Apr 23, 20241.24.0EOL
1.23Jun 21, 2022May 23, 20231.23.4EOL
1.22May 24, 2022Apr 11, 20231.22.1EOL
1.21May 25, 2021Jun 21, 20221.21.6EOL
1.20Apr 20, 2021May 24, 20221.20.2EOL
1.19May 26, 2020May 25, 20211.19.10EOL
1.18Apr 21, 2020Apr 20, 20211.18.0EOL
1.16Apr 23, 2019Apr 20, 20201.16.1EOL
1.14Apr 17, 2018Apr 23, 20191.14.2EOL
1.12Apr 12, 2017Apr 17, 20181.12.2EOL
1.10Apr 26, 2016Apr 12, 20171.10.3EOL
1.8Apr 21, 2015Apr 26, 20161.8.1EOL
1.6Apr 24, 2014Apr 21, 20151.6.3EOL
1.4Apr 24, 2013Apr 24, 20141.4.7EOL
1.2Apr 23, 2012Apr 24, 20131.2.9EOL
1.0Apr 12, 2011Apr 23, 20121.0.15EOL

CVEs affecting nginx 1.x (21)

CVESeverityCVSSEPSSKEVCycleDescriptionPublished
CVE-2026-49975HIGH7.527.98%1.6Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service vi…Jun 8, 2026
CVE-2026-49975HIGH7.527.98%1.18Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service vi…Jun 8, 2026
CVE-2026-49975HIGH7.527.98%1.25Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service vi…Jun 8, 2026
CVE-2026-49975HIGH7.527.98%1.0Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service vi…Jun 8, 2026
CVE-2026-49975HIGH7.527.98%1.21Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service vi…Jun 8, 2026
CVE-2026-49975HIGH7.527.98%1.29Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service vi…Jun 8, 2026
CVE-2026-49975HIGH7.527.98%1.27Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service vi…Jun 8, 2026
CVE-2026-49975HIGH7.527.98%1.14Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service vi…Jun 8, 2026
CVE-2026-49975HIGH7.527.98%1.24Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service vi…Jun 8, 2026
CVE-2026-49975HIGH7.527.98%1.2Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service vi…Jun 8, 2026
CVE-2026-49975HIGH7.527.98%1.26Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service vi…Jun 8, 2026
CVE-2026-49975HIGH7.527.98%1.16Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service vi…Jun 8, 2026
CVE-2026-49975HIGH7.527.98%1.22Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service vi…Jun 8, 2026
CVE-2026-49975HIGH7.527.98%1.20Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service vi…Jun 8, 2026
CVE-2026-49975HIGH7.527.98%1.10Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service vi…Jun 8, 2026
CVE-2026-49975HIGH7.527.98%1.12Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service vi…Jun 8, 2026
CVE-2026-49975HIGH7.527.98%1.8Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service vi…Jun 8, 2026
CVE-2026-49975HIGH7.527.98%1.4Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service vi…Jun 8, 2026
CVE-2026-49975HIGH7.527.98%1.23Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service vi…Jun 8, 2026
CVE-2026-49975HIGH7.527.98%1.19Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service vi…Jun 8, 2026
CVE-2026-49975HIGH7.527.98%1.28Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service vi…Jun 8, 2026

Frequently asked questions

Is nginx 1 end of life?

Partially. Some nginx 1.x releases have reached EOL. Check the version table above for the exact status of each sub-release.

What CVEs affect nginx 1?

There are 21 CVEs tracked for nginx 1.x. See the full list above with CVSS and EPSS scores.

What is the latest nginx 1 version?

The latest nginx 1.x patch release is 1.31.3, released on July 15, 2026. Always run the latest patch to benefit from all security fixes.

When was nginx 1 first released?

nginx 1.0 was initially released on May 13, 2026. See the full version timeline in the table above.

Is it safe to run nginx 1 in production?

nginx 1 is still supported and safe for production use. Ensure you are running the latest patch version (1.31.3) to have all security fixes applied.

Data sourced from endoflife.date · CVE data from NVD · EPSS from FIRST.org · KEV from CISA