News & Updates

Live Feed

Latest announcements, security advisories, and release updates for the Centmin Mod LEMP stack.

Latest from Community Forums

Project History & Announcements

2026
Security

Nginx 1.31.1 Security Update - 1 CVE Fixed (CVE-2026-9256)

Nginx 1.31.1 (mainline) and 1.30.2 (stable) have been released with a fix for 1 security vulnerability. All three Centmin Mod branches (132.00stable, 140.00beta01, 141.00beta01) have been updated to Nginx 1.31.1 as the new default.

CVE addressed:

  • CVE-2026-9256 - Heap buffer overflow in ngx_http_rewrite_module worker process when using a configuration with overlapping captures (potential arbitrary code execution)

To update, run cmupdate and then centmin.sh menu option 4 to recompile Nginx. Or instead of cmupdate, update your local code first via centmin.sh menu option 23 submenu option 2 and then centmin.sh menu option 4 to recompile Nginx. See the Nginx Upgrade / Downgrade guide for details.

By eva2000
Security

Nginx 1.31.0 Security Update - 6 CVEs Fixed

Nginx 1.31.0 (mainline) and 1.30.1 (stable) have been released with fixes for 6 security vulnerabilities. All three Centmin Mod branches (132.00stable, 140.00beta01, 141.00beta01) have been updated to Nginx 1.31.0 as the new default.

CVEs addressed:

  • CVE-2026-42945 - Heap buffer overflow in ngx_http_rewrite_module (potential code execution)
  • CVE-2026-42926 - HTTP/2 request injection via proxy_set_body
  • CVE-2026-42946 - Heap buffer overread in SCGI/uWSGI modules
  • CVE-2026-42934 - Heap buffer overread in UTF-8 charset decoding
  • CVE-2026-40460 - QUIC address spoofing via connection migration
  • CVE-2026-40701 - Use-after-free in DNS OCSP processing

To update, run cmupdate and then centmin.sh menu option 4 to recompile Nginx. Or instead of cmupdate, update your local code first via centmin.sh menu option 23 submenu option 2 and then centmin.sh menu option 4 to recompile Nginx. See the Nginx Upgrade / Downgrade guide and the forum announcement for more info.

By eva2000
Announcement

Centmin Mod 2026 Site Redesign

After over a decade running on the same design, the Centmin Mod website has been rebuilt from the ground up. The old site served us well, but it was showing its age - hard to read on phones, no dark mode, and documentation scattered across forum threads instead of being front and center on the site itself.

The new site fixes all of that. Every page now works properly on mobile, tablet, and desktop. There's a dark mode that follows your system preference or can be toggled manually. And most importantly, the documentation has been massively expanded with dedicated pages covering every major Centmin Mod feature in detail.

Here's what's new:

  • Over 50 documentation pages covering Nginx, PHP-FPM, MariaDB, SSL, firewalls, email, backups, and more
  • A comprehensive Menu Option 21 Data Management guide for backups, migrations, and S3 transfers
  • Improved installation instructions with step-by-step walkthroughs for AlmaLinux and Rocky Linux
  • An AI-powered search (press Cmd+K or click the search bar) that actually understands what you're looking for
  • An AI chatbot assistant that can answer technical questions about Centmin Mod configuration and troubleshooting
  • This live news feed you're reading right now, which automatically pulls the latest announcements from the community forums

The community forums remain the best place for support, bug reports, and discussions. The site and forums work together - the site provides the documentation and guides, while the forums handle the conversations and troubleshooting that need back-and-forth discussion.

If you spot any issues with the new site or have suggestions, feel free to post in the feedback and suggestions forum.

By eva2000
2024
2023
2022
2018
Release

Nginx TLS 1.3 Finally Here

Latest Centmin Mod 123.09beta01's Nginx 1.15.3+ now supports TLS v1.3 with two cryptographic libraries that can be built with Centmin Mod Nginx. Instructions for Nginx compiled with either BoringSSL or OpenSSL 1.1.1.

By eva2000
2017
2016
2015