NGINX Fixes Critical Poolslip Flaw Allowing Remote Code Execution
ID: 360b12fa-271f-5027-aaa2-0af4e4d5c81b
STIX ID: report--360b12fa-271f-5027-aaa2-0af4e4d5c81b
Feed Name: securityonline.info
F5/NGINX disclosed a severe heap buffer overflow vulnerability (CVE-2026-9256, “nginx-poolslip”) in NGINX Plus and Open Source triggered by rewrite directives using overlapping PCRE captures; unauthenticated HTTP requests can crash worker processes and, in environments where ASLR is disabled, may allow arbitrary code execution. Affected versions include NGINX Plus 37.0.0 and R32–R36 and Open Source 1.30.1/1.31.0; vendors released patches (e.g., 1.31.1, 1.30.2, 37.0.1.1) and recommend using named captures or applying the updates immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
