Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution
ID: 8fac5588-9bc4-53c6-9b6c-1879c7cd871c
STIX ID: report--8fac5588-9bc4-53c6-9b6c-1879c7cd871c
Feed Name: The Hacker News
F5 and nginx released patches (nginx 1.30.4 / 1.31.3 and NGINX Plus 37.0.3.1) for CVE-2026-42533, a critical heap buffer overflow in nginx's script engine triggered by a specific configuration involving regex-based map outputs and numbered captures; the flaw can cause worker crashes and may allow remote code execution where ASLR is disabled or bypassable. The vulnerability affects nginx versions from 0.9.6 through 1.31.2, is rated highly by F5 (CVSS v4 9.2), and a researcher reports a stronger RCE claim with a proof-of-concept planned, so immediate patching or temporary mitigations (switching to named captures) are advised.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
