This news broke on the weekend, and there is no CVE assigned (yet).
Eventually there will presumably be news at the NGINX security advisories site at https://nginx.org/en/security_advisories.html
That page says "All nginx security issues should be reported to [email protected]."
Any release information will probably also get announced on the Twitter, https://twitter.com/nginxorg
This news broke on the weekend, and there is no CVE assigned (yet).
Eventually there will presumably be news at the NGINX security advisories site at https://nginx.org/en/security_advisories.html
That page says "All nginx security issues should be reported to [email protected]."
Any release information will probably also get announced on the Twitter, https://twitter.com/nginxorg