logo

CVE-2026-42533: NGINX Memory Corruption via Map Directive Regex (CVSS 8.1)

ID: e86ad89e-504b-562a-b457-99e6eb25c056

STIX ID: report--e86ad89e-504b-562a-b457-99e6eb25c056

Feed Name: CosmicBytez Labs

Threat Score
72/100

Date Published: 2026-07-16

Date Updated: 2026-07-17

...
...

**NGINX CVE-2026-42533 — high-severity memory corruption:** A flaw in the NGINX map directive's lazy evaluation can lead to uninitialized or freed memory access when regex capture variables (or non-cacheable variables) are referenced before the map output, causing worker crashes, possible memory disclosure, and under some conditions potential arbitrary code execution; patches are available and configuration workarounds are provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.