
Source-built nginx 1.25.5 container with backported CVE-2026-42945 fix, OpenSSL bump, full provenance chain, and VEX attestation.
nginx:1.25-bookwormA source-built nginx 1.25.5 container image that remediates two CVEs present in
the official nginx:1.25-bookworm image while preserving upstream runtime behavior.
| CVE | Component | Severity | Technique | Verification model |
|---|---|---|---|---|
| CVE-2024-6119 | OpenSSL / libssl3 | High | Dependency version bump | Scanner-verifiable: libssl3 3.0.20 visible in dpkg database |
| CVE-2026-42945 | nginx ngx_http_rewrite_module | Critical | Backported source patch | Provenance-verifiable: patch derivation + regression test + build attestation + VEX |
These represent two distinct remediation models:
The nginx -V configure arguments of this image match those of
nginx:1.25-bookworm (compared character-by-character after normalizing the
-ffile-prefix-map build path; verified in test/compat.py::test_nginx_version).
The test suite (make test) validates 89 assertions covering image metadata,
dynamic modules, filesystem layout, entrypoint behavior, dpkg packaging, and
HTTP request handling against the live upstream image.
Known differences from upstream (not validated as identical):
built with OpenSSL X.X.X line in nginx -V reflects the builder's
libssl-dev version, which may differ from upstream's compile-time OpenSSL.debian:bookworm-slim base rather than the
official image's inherited package tree.libssl3 version is whatever bookworm currently provides (3.0.20
at time of writing), not the pinned version in the upstream image.# Build everything (builder → .deb → final image)
make image
# Run automated compatibility tests
make test
# Run CVE-2026-42945 regression test
make test-cve
# Verify patch provenance (re-derives from upstream tarballs)
make verify-patch
# Scan and demonstrate VEX
make scan
One command to build, test, and scan:
make all
build/
Dockerfile.build Builder image (debian:bookworm-slim + compilation deps)
build.sh Fetch → verify → patch → compile → package nginx
generate-vex.sh Generate OpenVEX document for backported CVE
verify-patch.sh Re-derive patch from upstream tarballs (audit tool)
patches/
CVE-2026-42945.patch Backported one-line fix from nginx 1.30.1
CVE-2026-42945.provenance.json Machine-readable patch provenance and derivation metadata
test/
compat.py 89-assertion compatibility test suite (runs against live upstream)
test_cve_2026_42945.py CVE-specific regression test (exercises vulnerable code path)
artifacts/
patch-attestation.json Build-time patch attestation (tracked)
nginx_*.deb Compiled package (gitignored - rebuilt via `make build-source`)
nginx Compiled binary (gitignored)
Containerfile Final runtime image definition
Makefile Orchestrates build → test → scan pipeline
vex.json Generated OpenVEX v0.2.0 document
baseline-trivy.txt Point-in-time Trivy scan of nginx:1.25-bookworm
baseline-grype.txt Point-in-time Grype scan of nginx:1.25-bookworm
fixed-trivy.txt Trivy scan of the fixed image
fixed-grype.txt Grype scan of the fixed image (without VEX)
fixed-grype-vex.txt Grype scan of the fixed image (with VEX applied)
debian:bookworm-slim (builder)
└─ build.sh
├─ curl nginx-1.25.5.tar.gz (SHA256-verified)
├─ curl njs-0.8.4 from github.com/nginx/njs
├─ patch -p1 < CVE-2026-42945.patch
├─ ./configure (flags identical to upstream nginx -V)
├─ make: release binary, debug binary, 4 dynamic module families (×2 release/debug)
├─ make: NJS modules (×2 release/debug) + njs CLI binary
└─ dpkg-deb → nginx_1.25.5-1~bookworm+echo1_<arch>.deb
debian:bookworm-slim (runtime)
├─ apt-get install runtime deps (libssl3 ≥ 3.0.14 enforced)
├─ dpkg -i nginx_*.deb
└─ COPY --from=upstream /docker-entrypoint.sh + /docker-entrypoint.d/
The Containerfile does NOT copy /etc/nginx from upstream. All configuration
files are shipped inside the .deb and tracked by dpkg's conffile mechanism.
This is required for the 10-listen-on-ipv6-by-default.sh entrypoint script,
which uses dpkg-query to detect whether default.conf has been user-modified.
./configure && make inside a clean Debian container.
No upstream binaries, no apt install nginx.build.sh only fetches pinned source archives.The build is mostly reproducible but not hermetic:
Dockerfile.build but not version-pinned.To improve reproducibility, pin the base image digest:
docker pull debian:bookworm-slim
docker inspect debian:bookworm-slim --format='{{index .RepoDigests 0}}'
# Then use: FROM debian:bookworm-slim@sha256:<digest>
| Field | Value |
|---|---|
| Component | OpenSSL / libssl3 |
| Severity | High (CVSS 7.5) |
| Type | Denial of Service via X.509 name checks |
| Baseline version | 3.0.11-1~deb12u2 |
| Fixed version | 3.0.14-1~deb12u2 (or later) |
| Our version | 3.0.20-1~deb12u1 |
| NVD | https://nvd.nist.gov/vuln/detail/CVE-2024-6119 |
| Advisory | https://openssl-library.org/news/secadv/20240903.txt |
How the fix works:
The .deb package declares Depends: libssl3 (>= 3.0.14), which forces
apt-get install to pull an OpenSSL version that includes the fix. The current
Debian bookworm repositories provide 3.0.20, which fixes CVE-2024-6119 and
dozens of other OpenSSL CVEs from the baseline (CVE-2024-2511, CVE-2024-5535,
CVE-2024-4741, CVE-2023-5678, CVE-2023-6129, CVE-2023-6237, CVE-2024-9143,
CVE-2025-15467, CVE-2025-69420).