CVE-2026-42533: NGINX Memory Corruption via Map Directive Regex (CVSS 8.1)
ID: e86ad89e-504b-562a-b457-99e6eb25c056
STIX ID: report--e86ad89e-504b-562a-b457-99e6eb25c056
Feed Name: CosmicBytez Labs
Threat Score
**NGINX CVE-2026-42533 — high-severity memory corruption:** A flaw in the NGINX map directive's lazy evaluation can lead to uninitialized or freed memory access when regex capture variables (or non-cacheable variables) are referenced before the map output, causing worker crashes, possible memory disclosure, and under some conditions potential arbitrary code execution; patches are available and configuration workarounds are provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
