See here for a changelog:
http://nginx.org/en/CHANGES-1.26
Fixes the following security issue:
CVE-2025-23419: Security: insufficient check in virtual servers handling
with TLSv1.3 SNI allowed to reuse SSL sessions in a different virtual
server, to bypass client SSL certificates verification
https://www.cve.org/CVERecord?id=CVE-2025-23419
Signed-off-by: Waldemar Brodkorb <wbx@openadk.org>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
(cherry picked from commit a7a18c2ef8)
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
5 lines
262 B
Plaintext
5 lines
262 B
Plaintext
# Locally calculated after checking pgp signature
|
|
sha256 69ee2b237744036e61d24b836668aad3040dda461fe6f570f1787eab570c75aa nginx-1.26.3.tar.gz
|
|
# License files, locally calculated
|
|
sha256 f19c4caea60247490199c5a6d0134281e3fb20b3d7577e6873c628597f5381d9 LICENSE
|