logo

Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution

ID: 8fac5588-9bc4-53c6-9b6c-1879c7cd871c

STIX ID: report--8fac5588-9bc4-53c6-9b6c-1879c7cd871c

Feed Name: The Hacker News

Threat Score
80/100

Date Published: 2026-07-19

Date Updated: 2026-07-20

Author: [email protected] (The Hacker News)

...
...

F5 and nginx released patches (nginx 1.30.4 / 1.31.3 and NGINX Plus 37.0.3.1) for CVE-2026-42533, a critical heap buffer overflow in nginx's script engine triggered by a specific configuration involving regex-based map outputs and numbered captures; the flaw can cause worker crashes and may allow remote code execution where ASLR is disabled or bypassable. The vulnerability affects nginx versions from 0.9.6 through 1.31.2, is rated highly by F5 (CVSS v4 9.2), and a researcher reports a stronger RCE claim with a proof-of-concept planned, so immediate patching or temporary mitigations (switching to named captures) are advised.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.