logo

NGINX Fixes Critical Poolslip Flaw Allowing Remote Code Execution

ID: 360b12fa-271f-5027-aaa2-0af4e4d5c81b

STIX ID: report--360b12fa-271f-5027-aaa2-0af4e4d5c81b

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-05-25

Date Updated: 2026-05-25

Author: Ddos

...
...

F5/NGINX disclosed a severe heap buffer overflow vulnerability (CVE-2026-9256, “nginx-poolslip”) in NGINX Plus and Open Source triggered by rewrite directives using overlapping PCRE captures; unauthenticated HTTP requests can crash worker processes and, in environments where ASLR is disabled, may allow arbitrary code execution. Affected versions include NGINX Plus 37.0.0 and R32–R36 and Open Source 1.30.1/1.31.0; vendors released patches (e.g., 1.31.1, 1.30.2, 37.0.1.1) and recommend using named captures or applying the updates immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.