Critical NGINX Heap Buffer Overflow CVE-2026-42533 Allows DoS and Potential RCE
F5 has patched a critical heap buffer overflow vulnerability in NGINX, tracked as CVE-2026-42533, which can crash worker processes and may allow…
F5 has patched a critical heap buffer overflow vulnerability in NGINX, tracked as CVE-2026-42533, which can crash worker processes and may allow…
A heap overflow in NGINX's rewrite module due to overlapping captures, disclosed in May 2026. Similar class of flaw as CVE-2026-42533, involving…
Mufeed VH of Winfunc Research is credited in NGINX changelog for helping fix CVE-2026-42533.
Okta's Red Team has disclosed a denial-of-service vulnerability in OpenSSL, dubbed HollowByte, that allows an attacker to freeze server memory using 11-byte…
NGINX versions 0.9.6 through 1.31.2 are vulnerable to CVE-2026-42533. Fixed in 1.30.4 and 1.31.3.
NGINX Open Source versions 1.31.0-1.31.1 are vulnerable to two critical remote code execution flaws; fixed in 1.31.2.
NGINX App Protect DoS versions 4.3.0-4.7.0 are affected by CVE-2026-42055.
F5 WAF for NGINX versions 5.9.0-5.13.1 are affected by CVE-2026-42055.
F5 DoS for NGINX version 4.9.0 is affected by CVE-2026-42055.
A heap overflow in NGINX's expression-evaluation code, disclosed in May 2026. Similar class of flaw as CVE-2026-42533, involving two-pass script engine. Exploit…