CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

Critical NGINX Heap Buffer Overflow CVE-2026-42533 Allows DoS and Potential RCE

July 19, 2026

F5 has patched a critical heap buffer overflow vulnerability in NGINX, tracked as CVE-2026-42533, which can crash worker processes and may allow remote code execution under certain conditions. The flaw resides in NGINX’s script engine and affects versions from 0.9.6 through 1.31.2, as well as NGINX Plus prior to 37.0.3.1. It requires a specific configuration involving regex-based maps and numbered captures, making exploitation dependent on server setup. F5 rates the vulnerability 9.2 on CVSS v4 and 8.1 on v3.1, noting high attack complexity. Researcher Stan Shaw (cyberstan) claims the flaw can bypass ASLR on default Ubuntu 24.04 builds, enabling RCE. The fix is to upgrade to NGINX 1.30.4, 1.31.3, or NGINX Plus 37.0.3.1. A temporary mitigation using named captures is available but incomplete. This is the third heap overflow in NGINX’s expression-evaluation code disclosed in two months, following CVE-2026-42945 (Rift) and CVE-2026-9256. No public exploit or CISA KEV listing exists as of July 20, but researchers warn of imminent exploit publication.

CVEs: CVE-2026-42533, CVE-2026-42945, CVE-2026-9256

Companies: F5, Winfunc Research, The Hacker News

Products: NGINX, NGINX Plus, NGINX Ingress Controller, NGINX Gateway Fabric, NGINX App Protect WAF, NGINX Instance Manager