Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - wirehire

#2
26.1, 26,4 Series / Re: cve nginx
June 22, 2026, 08:13:31 PM
based on apache right?  we have problems (speed , latency) with apache reverse, so we come to nginx. but thanks for your input. we are looking forward to evalutate this plugin as alternate to os-nginx.


greets
#3
26.1, 26,4 Series / Re: cve nginx
June 22, 2026, 07:47:29 PM
thanks for the insights! We have 6 business firewalls, where nginx run as a  reverse proxy and automatic scanners, which note when it comes to critical cve. So when nginx are focus for community , we musst look to change the reverse proxy package or away from the opnsense as a reverse proxy to a server.

Greets!
#4
26.1, 26,4 Series / Re: cve nginx
June 22, 2026, 03:16:56 PM
hey franco, first thanks for the answer. i see it in the vuxml and i see the new release with the fixes.

i want understood, how the updates from core come to opnsense. the core packages are always from the upstream when i hit the update button? or only when your team it allow in the opnsense repo?

greets , i hope i make my question clear for unstanding.

greets!
#5
26.1, 26,4 Series / cve nginx
June 21, 2026, 05:19:11 PM
https://nginx.org/en/security_advisories.html

the nginx comes from freebsd upstream ? because last time , its was long delayed , when it comes to the opnsense repo.

How can we update a critical ( nginx) only wait or can we force update from freebsd?

Greets
#6
There are still a lot of Vodafone numbers on the list. can you share why?
#7
indeed, many vodafone ips are on the blocklist now, with good reputation.
#8
thanks franco and the team. we are now updated all our firewall to 26.4 Business!

Work like a charme! very good work, thanks for your software !
#9
thanks, i look and found nothing. but zero trust on me , so i wait for the patch , and closed the front.

i though the packages come directly from freebsd , so a okg update ngixn worked. so thanks for the inside!

#10
so the fix is not in the version. it is possible to update from the cli? or only wait for the new plugin?
#11


Hey,

which version runs on the opnsense plugin for nginx?

https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=295270

it came a to a critical heat buffer overflow.

Greets
#12
so as example on 25.10 , we can on the cli /shell opnsense-patch , as example the sctp cve ?

as i see , you are in germany, have a good free day and long weekend!
#13
thanks franco,

you and your team are awesome!

Is it possible to release the CVE patches that have been backported for 25.10? There are still some users who haven't upgraded to 26.4 yet because they're still in the testing phase and the rollout hasn't started yet (since a lot has changed).

greets
#14
Franco, I really appreciate your work! There's no question about that. The only question was how critical this vulnerability is, and it currently appears that it doesn't need to be patched immediately. Is that correct?
#15
Hey,

i saw that the community edition are become the fixes for several cve. What are with the business edition? give it the patches for 25.10 and for 26.4?

like CVE-2026-7164

greets