nginx-1.27.4

2025-02-05 Thread Sergey Kandaurov
Changes with nginx 1.27.405 Feb 2025 *) Security: insufficient check in virtual servers handling with TLSv1.3 SNI allowed to reuse SSL sessions in a different virtual server, to bypass client SSL certificates verification (CVE-2025-23419).

nginx-1.26.3

2025-02-05 Thread Sergey Kandaurov
Changes with nginx 1.26.305 Feb 2025 *) Security: insufficient check in virtual servers handling with TLSv1.3 SNI allowed to reuse SSL sessions in a different virtual server, to bypass client SSL certificates verification (CVE-2025-23419).