CVE-2026-42533

Published Jul 15, 2026

Last updated 5 days ago

CVSS critical 9.2
NGINX Plus
NGINX Open Source

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-42533 is a heap buffer overflow vulnerability affecting NGINX Plus and NGINX Open Source. This flaw arises when the `map` directive utilizes regular expression matching, and a string expression references the map's regex capture variables prior to referencing the map output variable. The same outcome can also be achieved under specific conditions by employing a non-cacheable variable within a string expression. An unauthenticated attacker can exploit this vulnerability by sending specially crafted HTTP requests. This can lead to a heap buffer overflow in the NGINX worker process, which may result in a restart of the process. The vulnerability is described as a configuration-dependent worker-process memory corruption issue.

Description
A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the map's regex capture variables before referencing the map output variable. Alternatively, the same result could be achieved by using a non-cacheable variable in a string expression under certain conditions. An unauthenticated attacker along with conditions beyond their control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Impact: This vulnerability may allow remote attackers to cause a denial-of-service (DoS) on the NGINX system or to possibly trigger a code execution. There is no control plane exposure; this is a data plane issue only.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Source
f5sirt@f5.com
NVD status
Awaiting Analysis

Risk scores

CVSS 4.0

Type
Secondary
Base score
9.2
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
CRITICAL

CVSS 3.1

Type
Secondary
Base score
8.1
Impact score
5.9
Exploitability score
2.2
Vector string
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

f5sirt@f5.com
CWE-122

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

1

  1. Recent critical flaws: NGINX (CVE-2026-42533) risks DoS/RCE, OpenSSL HollowByte can freeze TLS servers, and WordPress RCE (CVE-2026-63030) endangers backend data. These actively threaten data privacy & integrity in transit. #Cybersecurity #Vulnerabilities #News

    @YourAnon_irc

    21 Jul 2026

    19 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. 🚨 @nginxorg users, this is one to prioritize. A critical heap buffer overflow (CVE-2026-42533, CVSS 9.2) has been disclosed in both NGINX Open Source and NGINX Plus. The advisory also patches: • Memory disclosure (CVE-2026-60005) • Use-after-free (CVE-2026-56434) Most

    @jxngrx

    21 Jul 2026

    17 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  3. 🛑 NGINX CVE-2026-42533 turns a narrow map regex bug into an urgent patch… F5 and NGINX patched CVE-2026-42533, a critical map regex buffer overflow that can crash wo… 🔗 Details → https://t.co/9hh0ddM6Zv

    @lucasverdan

    20 Jul 2026

    56 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. 15-Year-Old Pre-Auth nginx RCE Across 13 Call Sites: Two-Pass Capture Clobbering CVE-2026-42533 – cyberstan https://t.co/zQAs2b49FG"CVE-2026-42533 · Fixed in nginx 1.30.4 / 1.31.3 · Affected: nginx 0.9.6 through 1.30.3 (stable) and 1.31.2 (mainline) · NGINX Plus R33–R36 (f

    @catnap707

    20 Jul 2026

    232 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  5. Eine neue Trending CVE (CVE-2026-42533, CVSS 9.2) betrifft NGINX Open Source und NGINX Plus. Details 👉 https://t.co/1zmoGBH55r #CVE #Vulnerability #nginx

    @VulnDex

    20 Jul 2026

    2 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. F5 released patches for a critical NGINX flaw (CVE-2026-42533) that can let remote attackers crash servers and potentially achieve remote code execution. 📌 Full Details: 🔗 https://t.co/2dfM8UbCb0 #nginx #vulnerability https://t.co/MXtHjDc9VX

    @ncn_english

    19 Jul 2026

    16 Impressions

    0 Retweets

    3 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. أصدرت إنجن إكس تحديثات أمنية لمعالجة ثغرة حرجة تحمل المعرف CVE-2026-42533، والتي قد تسمح لمهاجم عن بُعد، دون الحاجة إلى مصادقة، بتعطيل خوادم الويب، وفي بعض الحا

    @ncnarabic

    19 Jul 2026

    42 Impressions

    0 Retweets

    3 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. Third time in months. 🧵 nginx just took another critical pre-auth RCE — and this one's been in the code since 2011. CVE-2026-42533 · CVSS 9.2 · patched July 15. If you run nginx, patch to 1.30.4 / 1.31.3 now. Here's why it matters 👇 https://t.co/WjwROID0U2

    @cyberkendra

    19 Jul 2026

    92 Impressions

    1 Retweet

    0 Likes

    1 Bookmark

    1 Reply

    0 Quotes

  9. #Analytics #Threat_Research An analytical review of the main cybersecurity events (July 05 - 18, 2026) 1⃣  NGINX Vulnerability https://t.co/n5vlIjDyc9 // NGINX map Directive Heap Overflow and Data Plane Risk (CVE-2026-42533) 2⃣  Zoom Account Takeover Patch

    @ksg93rd

    19 Jul 2026

    193 Impressions

    1 Retweet

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. Pre-Auth nginx RCE Across 13 Call Sites: Two-Pass Capture Clobbering CVE-2026-42533 Credit/Author: Cyberstan His blog: https://t.co/ZPgNTTE1l9 https://t.co/2ahfucUJ57

    @7h3h4ckv157

    19 Jul 2026

    9916 Impressions

    20 Retweets

    109 Likes

    48 Bookmarks

    1 Reply

    1 Quote

  11. Here's the AILA write-up for CVE-2026-42533 - TwinWalk with PoC It started with a single prompt for CVE-2026-42945 and it spawned 378 sub investigations. 127M input tokens / 21M output tokens are burned and it costed me nothing. (free tier models)

    @echel0n_1881

    18 Jul 2026

    61 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  12. nginx releases security updates (1.30.4 & 1.31.3): Fixes include: • CVE-2026-42533 – Buffer overflow • CVE-2026-60005 – Memory disclosure • CVE-2026-56434 – Use-after-free Update as soon as possible. #nginx #Vulnerability

    @ThreatByte

    17 Jul 2026

    4 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  13. 🚨 CVE-2026-42533, CVE-2026-60005 & CVE-2026-56434: F5 has disclosed three high-severity vulnerabilities affecting NGINX Plus and NGINX Open Source, potentially leading to memory corruption, worker crashes, or remote code execution. #CyberSecurity #CVE #NGINX #F5 #ThreatWi

    @ThreatWire_

    16 Jul 2026

    52 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  14. 🔴 NGINX kullanıcılarının dikkatine! F5, NGINX ve NGINX Plus'ı etkileyen 3 yüksek önem dereceli güvenlik açığını duyurdu. • CVE-2026-42533 – Heap Buffer Overflow • CVE-2026-60005 – Uninitialized Memory Disclosure • CVE-2026-56434 – Use-After-Free Etk

    @ridvanyagli

    16 Jul 2026

    197 Impressions

    1 Retweet

    2 Likes

    2 Bookmarks

    0 Replies

    0 Quotes

  15. NGINX release-1.30.4 patches CVE-2026-42533 Critical security vulnerabilities (CVE-2026-42533, CVE-2026-60005, CVE-2026-56434) fixed. Upgrade carefully. → https://t.co/aKovKRAYKK

    @ReleasePort

    16 Jul 2026

    11 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  16. F5 patched the NGINX code execution flaw CVE-2026-42533, along with CVE-2026-60005 and CVE-2026-56434. Update NGINX Plus and Open Source builds now. #NGINX #CVE202642533 #CodeExecution #F5 #Vulnerability https://t.co/cds4Vr6BxO

    @Daily_CyberSec

    16 Jul 2026

    571 Impressions

    2 Retweets

    9 Likes

    3 Bookmarks

    0 Replies

    0 Quotes

References

Sources include official advisories and independent security research.