CVE-2026-42533 Exposes Critical Pre-Auth nginx RCE Flaw
ID: c3ed06ae-9d12-5822-ade0-99b67f26f8e8
STIX ID: report--c3ed06ae-9d12-5822-ade0-99b67f26f8e8
Feed Name: The Cyber Express
**CVE-2026-42533 — Critical pre-auth nginx RCE:** A two-pass PCRE capture-state bug in nginx allows attackers to trigger a heap overflow and leak heap pointers (defeating ASLR) via configurations combining regex map variables and regex captures, enabling reliable unauthenticated remote code execution; affected open-source nginx versions include 0.9.6–1.30.3 (stable) and 1.31.2 (mainline) and several NGINX Plus releases. Researchers achieved consistent exploitation in testing and advise immediate upgrade to nginx 1.30.4 / 1.31.3 or the corresponding patched NGINX Plus releases and auditing of vulnerable configuration patterns.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
