CVE-2026-42533: Critical NGINX Bug Could Turn HTTP Requests Into Server Takeovers
ID: 70f57594-8866-538f-a8cc-8da0c609056b
STIX ID: report--70f57594-8866-538f-a8cc-8da0c609056b
Feed Name: Security Affairs
Threat Score
F5 disclosed a critical NGINX vulnerability (CVE-2026-42533, CVSS 9.2) where specially crafted HTTP requests against regex-based map configurations can trigger a heap buffer overflow, leading to crashes and, in some circumstances (e.g., ASLR bypass), remote code execution; patches and workarounds have been released and researchers have published a static scanner while delaying PoC release to allow patching.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
