[Pkg-nginx-maintainers] Bug#1143087: Nginx: Possible log forgery when using error_log
Jérémy Lal
kapouer at melix.org
Thu Jul 30 11:55:59 BST 2026
Package: nginx
Version: 1.30.1-7+b1
Followup-For: Bug #1143087
Control: tags -1 + confirmed
Also access log doesn't have that issue:
::1 - - [30/Jul/2026:12:32:33 +0200] "GET /%0A2026/07/30%2013:66:66%20oops%0A2026/07/30%2013:66:66%20 HTTP/1.1" 404 146 "-" "curl/8.21.0"
I thought both error_log and access_log had the same default log_format "combined".
-- System Information:
Debian Release: forky/sid
APT prefers unstable
APT policy: (500, 'unstable'), (500, 'testing'), (1, 'experimental')
Architecture: amd64 (x86_64)
Kernel: Linux 7.1.4+deb14-amd64 (SMP w/4 CPU threads; PREEMPT)
Locale: LANG=fr_FR.utf8, LC_CTYPE=fr_FR.utf8 (charmap=UTF-8), LANGUAGE not set
Shell: /bin/sh linked to /usr/bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled
Versions of packages nginx depends on:
ii libc6 2.42-17
ii libcrypt1 1:4.5.1-1+b1
ii libpcre2-8-0 10.46-1+b2
ii libssl3t64 3.6.3-1
ii nginx-common 1.30.1-7
ii zlib1g 1:1.3.dfsg+really1.3.2-3
nginx recommends no packages.
nginx suggests no packages.
-- debconf information excluded
More information about the Pkg-nginx-maintainers
mailing list