Nginx CVE-2026-42945

Has anyone checked if Discourse containers are vulnerable to this rewrite vulnerability?

This is not a Discourse issue and topics regarding it should not be opened here.

We will update our base image our default rewrite rules are not vulnerable

This has now been completed.

The base image now includes NGINX 1.30.1 :

and the default image was bumped to the new base image: