Wingetlywingetly
← All apps

nginx

by nginxv1.31.6

Last updated

NGINX is the world's most popular Web Server, high performance Load Balancer, Reverse Proxy, API Gateway and Content Cache.

Install with winget

$ winget install --id nginxinc.nginx --exact --version 1.31.6

Run in Command Prompt, PowerShell, or Windows Terminal. Prompts for any agreements.

Built by Pckgr

For Intune admins

Stop chasing app updates. Pckgr patches them for you.

Automated application patching for Microsoft Intune. Pckgr keeps a curated library of 1,000+ apps continuously up-to-date in your tenant via Microsoft Graph - no manual repackaging, no chasing vendor sites.

Start free 30-day trial

No credit card required.

Installers · v1.31.6

ArchitectureTypeScopeInstallDownload
x64ZIP
archive
-Direct

Copy a command tailored to that specific architecture, type, and scope - useful when winget would otherwise pick a different default.

Security

16 known CVEs via NVD

  • medium4.8Patched in wingetCVE-2026-48142affects >=1.0.0 and <=1.30.2Jun 17, 2026

    NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When content is served or proxied through a location block with both source_charset utf-8; and a charset directive (for example, charset koi8-r;) configured, remote, unauthenticated atta...

  • high7.8Patched in wingetCVE-2026-32647affects before 1.28.3, 1.29.7Mar 24, 2026

    NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module module, which might allow an attacker to trigger a buffer over-read or over-write to the NGINX worker memory resulting in its termination or possibly code execution, using a specially crafted MP4 fi...

  • medium5.4Patched in wingetCVE-2026-28755affects before 1.28.3, 1.29.7Mar 24, 2026

    NGINX Plus and NGINX Open Source have a vulnerability in the ngx_stream_ssl_module module due to the improper handling of revoked certificates when configured with the ssl_verify_client on and ssl_ocsp on directives, allowing the TLS handshake to succeed even after an OCSP check...

  • low3.7Patched in wingetCVE-2026-28753affects before 1.28.3, 1.29.7Mar 24, 2026

    NGINX Plus and NGINX Open Source have a vulnerability in the ngx_mail_smtp_module module due to the improper handling of CRLF sequences in DNS responses. This allows an attacker-controlled DNS server to inject arbitrary headers into SMTP upstream requests, leading to potential r...

  • high7.8Patched in wingetCVE-2026-27784affects before 1.28.3, 1.29.7Mar 24, 2026

    The 32-bit implementation of NGINX Open Source has a vulnerability in the ngx_http_mp4_module module, which might allow an attacker to over-read or over-write NGINX worker memory resulting in its termination, using a specially crafted MP4 file. The issue only affects 32-bit NGIN...

  • high8.2Patched in wingetCVE-2026-27654affects before 1.28.3, 1.29.7Mar 24, 2026

    NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_dav_module module that might allow an attacker to trigger a buffer overflow to the NGINX worker process; this vulnerability may result in termination of the NGINX worker process or modification of source or de...

  • high7.5Patched in wingetCVE-2026-27651affects before 1.28.3, 1.29.7Mar 24, 2026

    When the ngx_mail_auth_http_module module is enabled on NGINX Plus or NGINX Open Source, undisclosed requests can cause worker processes to terminate. This issue may occur when (1) CRAM-MD5 or APOP authentication is enabled, and (2) the authentication server permits retry by ret...

  • medium5.9Patched in wingetCVE-2026-1642affects before 1.28.2, 1.29.5Feb 4, 2026

    A vulnerability exists in NGINX OSS and NGINX Plus when configured to proxy to upstream Transport Layer Security (TLS) servers. An attacker with a man-in-the-middle (MITM) position on the upstream server side—along with conditions beyond the attacker's control—may be able to inj...

Showing 8 of 16. Source: NVD, updated just now. Patch status is best-effort: NVD's fix version is compared against the latest version in winget, but the two version formats don't always align. Confirm with the vendor advisory before treating any specific build as safe.

See a CVE that affects your fleet? Push the patched version to Intune in one click with Pckgr - automated patching is the only way to keep up.

Related apps

  • N
    nginx-prometheus-exporternginx
    nginx.nginx-prometheus-exporterv1.5.3

    NGINX Prometheus Exporter for NGINX and NGINX Plus

More from nginx.

Frequently asked questions

How do I install nginx on Windows?
Open Windows Terminal, PowerShell, or Command Prompt and run: winget install --id nginxinc.nginx --exact --version 1.31.6. winget downloads the installer from nginx and runs it. Requires Windows 10 (1809+) or Windows 11.
How do I install nginx silently for unattended deployment?
Add --silent and accept the agreements upfront: winget install --id nginxinc.nginx --exact 1.31.6 --silent --accept-package-agreements --accept-source-agreements. This is the variant Intune, Configuration Manager, and other deployment tools should use.
How do I uninstall nginx via winget?
Run: winget uninstall --id nginxinc.nginx --exact. Add --silent for unattended uninstalls. winget will use the registered uninstaller from nginx's Apps & Features entry.
Is nginx free?
nginx is distributed under BSD-2-Clause. Refer to the publisher (https://nginx.org/) for the full license terms - Wingetly itself does not charge for installation.
Does nginx work on Windows 10?
Yes, as long as your Windows 10 build supports winget (1809 or newer). winget ships with App Installer on Windows 10/11 and pulls nginx directly from the publisher.
How do I keep nginx up to date?
Run winget upgrade --id nginxinc.nginx --exact, or winget upgrade --all to update everything winget tracks. We index 10 versions of nginx from microsoft/winget-pkgs.

Recent versions

  • 1.31.6latest
  • 1.31.5
  • 1.31.4
  • 1.31.3
  • 1.31.2
  • 1.31.1
  • 1.31.0
  • 1.29.8
  • 1.29.7
  • 1.29.6