nginx 1.x — End of Life
Active Actively exploitednginx 1.x — All releases
| Version | Released | Active support | EOL date | Latest patch | Status | Alert me |
|---|---|---|---|---|---|---|
| 1.31 | May 13, 2026 | — | No | 1.31.5 | Active | |
| 1.30 | Apr 14, 2026 | — | No | 1.30.4 | Active | |
| 1.29 | Jun 24, 2025 | — | May 13, 2026 | 1.29.8 | EOL | |
| 1.28 | Apr 23, 2025 | — | Apr 14, 2026 | 1.28.3 | EOL | |
| 1.27 | May 28, 2024 | — | Jun 24, 2025 | 1.27.5 | EOL | |
| 1.26 | Apr 23, 2024 | — | Apr 23, 2025 | 1.26.3 | EOL | |
| 1.25 | May 23, 2023 | — | May 29, 2024 | 1.25.5 | EOL | |
| 1.24 | Apr 11, 2023 | — | Apr 23, 2024 | 1.24.0 | EOL | |
| 1.23 | Jun 21, 2022 | — | May 23, 2023 | 1.23.4 | EOL | |
| 1.22 | May 24, 2022 | — | Apr 11, 2023 | 1.22.1 | EOL | |
| 1.21 | May 25, 2021 | — | Jun 21, 2022 | 1.21.6 | EOL | |
| 1.20 | Apr 20, 2021 | — | May 24, 2022 | 1.20.2 | EOL | |
| 1.19 | May 26, 2020 | — | May 25, 2021 | 1.19.10 | EOL | |
| 1.18 | Apr 21, 2020 | — | Apr 20, 2021 | 1.18.0 | EOL | |
| 1.16 | Apr 23, 2019 | — | Apr 20, 2020 | 1.16.1 | EOL | |
| 1.14 | Apr 17, 2018 | — | Apr 23, 2019 | 1.14.2 | EOL | |
| 1.12 | Apr 12, 2017 | — | Apr 17, 2018 | 1.12.2 | EOL | |
| 1.10 | Apr 26, 2016 | — | Apr 12, 2017 | 1.10.3 | EOL | |
| 1.8 | Apr 21, 2015 | — | Apr 26, 2016 | 1.8.1 | EOL | |
| 1.6 | Apr 24, 2014 | — | Apr 21, 2015 | 1.6.3 | EOL | |
| 1.4 | Apr 24, 2013 | — | Apr 24, 2014 | 1.4.7 | EOL | |
| 1.2 | Apr 23, 2012 | — | Apr 24, 2013 | 1.2.9 | EOL | |
| 1.0 | Apr 12, 2011 | — | Apr 23, 2012 | 1.0.15 | EOL |
CVEs affecting nginx 1.x (33)
| CVE | Severity | CVSS | EPSS | KEV | Cycle | Description | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-49975 | HIGH | 7.5 | 31.04% | — | 1.28 | Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service vi… | Jun 8, 2026 |
| CVE-2026-49975 | HIGH | 7.5 | 31.04% | — | 1.18 | Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service vi… | Jun 8, 2026 |
| CVE-2026-49975 | HIGH | 7.5 | 31.04% | — | 1.2 | Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service vi… | Jun 8, 2026 |
| CVE-2026-49975 | HIGH | 7.5 | 31.04% | — | 1.26 | Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service vi… | Jun 8, 2026 |
| CVE-2026-49975 | HIGH | 7.5 | 31.04% | — | 1.16 | Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service vi… | Jun 8, 2026 |
| CVE-2026-49975 | HIGH | 7.5 | 31.04% | — | 1.22 | Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service vi… | Jun 8, 2026 |
| CVE-2026-49975 | HIGH | 7.5 | 31.04% | — | 1.20 | Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service vi… | Jun 8, 2026 |
| CVE-2026-49975 | HIGH | 7.5 | 31.04% | — | 1.10 | Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service vi… | Jun 8, 2026 |
| CVE-2026-49975 | HIGH | 7.5 | 31.04% | — | 1.12 | Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service vi… | Jun 8, 2026 |
| CVE-2026-49975 | HIGH | 7.5 | 31.04% | — | 1.8 | Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service vi… | Jun 8, 2026 |
| CVE-2026-49975 | HIGH | 7.5 | 31.04% | — | 1.4 | Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service vi… | Jun 8, 2026 |
| CVE-2026-49975 | HIGH | 7.5 | 31.04% | — | 1.23 | Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service vi… | Jun 8, 2026 |
| CVE-2026-49975 | HIGH | 7.5 | 31.04% | — | 1.19 | Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service vi… | Jun 8, 2026 |
| CVE-2026-49975 | HIGH | 7.5 | 31.04% | — | 1.6 | Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service vi… | Jun 8, 2026 |
| CVE-2026-49975 | HIGH | 7.5 | 31.04% | — | 1.25 | Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service vi… | Jun 8, 2026 |
| CVE-2026-49975 | HIGH | 7.5 | 31.04% | — | 1.0 | Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service vi… | Jun 8, 2026 |
| CVE-2026-49975 | HIGH | 7.5 | 31.04% | — | 1.21 | Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service vi… | Jun 8, 2026 |
| CVE-2026-49975 | HIGH | 7.5 | 31.04% | — | 1.29 | Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service vi… | Jun 8, 2026 |
| CVE-2026-49975 | HIGH | 7.5 | 31.04% | — | 1.27 | Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service vi… | Jun 8, 2026 |
| CVE-2026-49975 | HIGH | 7.5 | 31.04% | — | 1.14 | Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service vi… | Jun 8, 2026 |
| CVE-2026-49975 | HIGH | 7.5 | 31.04% | — | 1.24 | Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service vi… | Jun 8, 2026 |
| CVE-2023-44487 | HIGH | 7.5 | 99.99% | KEV | 1.18 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many… | Oct 10, 2023 |
| CVE-2023-44487 | HIGH | 7.5 | 99.99% | KEV | 1.20 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many… | Oct 10, 2023 |
| CVE-2023-44487 | HIGH | 7.5 | 99.99% | KEV | 1.25 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many… | Oct 10, 2023 |
| CVE-2023-44487 | HIGH | 7.5 | 99.99% | KEV | 1.19 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many… | Oct 10, 2023 |
| CVE-2023-44487 | HIGH | 7.5 | 99.99% | KEV | 1.10 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many… | Oct 10, 2023 |
| CVE-2023-44487 | HIGH | 7.5 | 99.99% | KEV | 1.21 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many… | Oct 10, 2023 |
| CVE-2023-44487 | HIGH | 7.5 | 99.99% | KEV | 1.16 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many… | Oct 10, 2023 |
| CVE-2023-44487 | HIGH | 7.5 | 99.99% | KEV | 1.23 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many… | Oct 10, 2023 |
| CVE-2023-44487 | HIGH | 7.5 | 99.99% | KEV | 1.22 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many… | Oct 10, 2023 |
| CVE-2023-44487 | HIGH | 7.5 | 99.99% | KEV | 1.14 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many… | Oct 10, 2023 |
| CVE-2023-44487 | HIGH | 7.5 | 99.99% | KEV | 1.12 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many… | Oct 10, 2023 |
| CVE-2023-44487 | HIGH | 7.5 | 99.99% | KEV | 1.24 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many… | Oct 10, 2023 |
Frequently asked questions
Is nginx 1 end of life?
Partially. Some nginx 1.x releases have reached EOL. Check the version table above for the exact status of each sub-release.
What CVEs affect nginx 1?
There are 33 CVEs tracked for nginx 1.x and 12 listed in the CISA Known Exploited Vulnerabilities catalog. See the full list above with CVSS and EPSS scores.
What is the latest nginx 1 version?
The latest nginx 1.x patch release is 1.31.5, released on September 2, 2026. Always run the latest patch to benefit from all security fixes.
When was nginx 1 first released?
nginx 1.0 was initially released on May 13, 2026. See the full version timeline in the table above.
Is it safe to run nginx 1 in production?
nginx 1 is still supported and safe for production use. Ensure you are running the latest patch version (1.31.5) to have all security fixes applied.
Data sourced from endoflife.date · CVE data from NVD · EPSS from FIRST.org · KEV from CISA
